Reblogged by jsonstein@masto.deoan.org ("Jeff Sonstein"):
vegard ("Vegard Nossum") wrote:
Upstream backdoor discovered in xz-utils/liblzma: https://www.openwall.com/lists/oss-security/2024/03/29/4
It seems to affect ssh authentication.
As far as we know, only xz-utils 5.6.0/5.6.1 are affected and these are luckily not yet widely deployed.