Mastodon Feed: Post

Mastodon Feed

Reblogged by kornel ("Kornel"):

barometz@tech.lgbt ("dominic") wrote:

After observing a few odd symptoms around liblzma (part of the xz package) on
Debian sid installations over the last weeks (logins with ssh taking a lot of
CPU, valgrind errors) I figured out the answer:

The upstream xz repository and the xz tarballs have been backdoored.

have a good weekend everybody!

https://www.openwall.com/lists/oss-security/2024/03/29/4