Reblogged by kornel ("Kornel"):
barometz@tech.lgbt ("dominic") wrote:
After observing a few odd symptoms around liblzma (part of the xz package) on
Debian sid installations over the last weeks (logins with ssh taking a lot of
CPU, valgrind errors) I figured out the answer:The upstream xz repository and the xz tarballs have been backdoored.
have a good weekend everybody!