574
Arch with XZ (lemmy.world)
you are viewing a single comment's thread
view the rest of the comments
[-] lemmyvore@feddit.nl 92 points 1 year ago

I thought Arch was the only rolling distro that doesn't have the backdoor. Its sshd is not linked with liblzma, and even if it were, they compile xz directly from git so they wouldn't have gotten the backdoor anyway.

[-] angel@iusearchlinux.fyi 32 points 1 year ago

TBF they only switched to building from git after they were notified of the backdoor yesterday. Prior to that, the source tarball was used.

[-] qwioeue@lemmy.world 25 points 1 year ago* (last edited 1 year ago)

liblzma is the problem. sshd is just the first thing they found that it is attacking. liblzma is used by firefox and many other critical packages.

[-] qupada@kbin.social 11 points 1 year ago* (last edited 1 year ago)

Interestingly, looking at Gentoo's package, they have both the github and tukaani.org URLs listed:

https://github.com/gentoo/gentoo/blob/master/app-arch/xz-utils/xz-utils-5.6.1.ebuild#L28

From what I understand, those wouldn't be the same tarball, and might have thrown an error.

[-] possiblylinux127@lemmy.zip 3 points 1 year ago

The extent of the exploit is still being analyzed so I would update and keep your eye on the news. If you don't need your computer you could always power down.

this post was submitted on 30 Mar 2024
574 points (100.0% liked)

linuxmemes

24389 readers
266 users here now

Hint: :q!


Sister communities:


Community rules (click to expand)

1. Follow the site-wide rules

2. Be civil
  • Understand the difference between a joke and an insult.
  • Do not harrass or attack users for any reason. This includes using blanket terms, like "every user of thing".
  • Don't get baited into back-and-forth insults. We are not animals.
  • Leave remarks of "peasantry" to the PCMR community. If you dislike an OS/service/application, attack the thing you dislike, not the individuals who use it. Some people may not have a choice.
  • Bigotry will not be tolerated.
  • 3. Post Linux-related content
  • Including Unix and BSD.
  • Non-Linux content is acceptable as long as it makes a reference to Linux. For example, the poorly made mockery of sudo in Windows.
  • No porn, no politics, no trolling or ragebaiting.
  • 4. No recent reposts
  • Everybody uses Arch btw, can't quit Vim, <loves/tolerates/hates> systemd, and wants to interject for a moment. You can stop now.
  • 5. ๐Ÿ‡ฌ๐Ÿ‡ง Language/ัะทั‹ะบ/Sprache
  • This is primarily an English-speaking community. ๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ฆ๐Ÿ‡บ๐Ÿ‡บ๐Ÿ‡ธ
  • Comments written in other languages are allowed.
  • The substance of a post should be comprehensible for people who only speak English.
  • Titles and post bodies written in other languages will be allowed, but only as long as the above rule is observed.
  • 6. (NEW!) Regarding public figuresWe all have our opinions, and certain public figures can be divisive. Keep in mind that this is a community for memes and light-hearted fun, not for airing grievances or leveling accusations.
  • Keep discussions polite and free of disparagement.
  • We are never in possession of all of the facts. Defamatory comments will not be tolerated.
  • Discussions that get too heated will be locked and offending comments removed.
  • ย 

    Please report posts and comments that break these rules!


    Important: never execute code or follow advice that you don't understand or can't verify, especially here. The word of the day is credibility. This is a meme community -- even the most helpful comments might just be shitposts that can damage your system. Be aware, be smart, don't remove France.

    founded 2 years ago
    MODERATORS