Reported Supply Chain Compromise Affecting XZ Utils Data Compression Library, CVE-2024-3094

Discussion in 'other security issues & news' started by ronjor, Mar 29, 2024.

  1. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    177,086
    Location:
    Texas
    Release Date March 29, 2024
    Red Hat: Urgent security alert for Fedora 41 and Rawhide users
     
  2. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,224
    Location:
    Member state of European Union
    That's huge. Kudos for discovering it before it entered stable version of any major distro.
    Personally I switched to use tar+7z combo for ad-hoc directory archivization, but probably lots of other tools my use it.
     
  3. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,224
    Location:
    Member state of European Union
    Disclosure on openwall: https://www.openwall.com/lists/oss-security/2024/03/29/4

    GitHub Disables The XZ Repository Following Today's Malicious Disclosure
    https://www.phoronix.com/news/GitHub-Disables-XZ-Repo
    Personally I moved on some years ago to (p)7zip for small ad-hoc archives and Zstd for big backups, because xz seemed to not be maintained at stable pace, and downstream xz packages were also not up to date in some distributions. I hope that same fate won't happen to other compression tools.
     
  4. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    177,086
    Location:
    Texas
  5. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,224
    Location:
    Member state of European Union
    https://www.bleepingcomputer.com/news/security/new-xz-backdoor-scanner-detects-implant-in-any-linux-binary/

    It is worth to remind that complete reinstall of affected systems is advised.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice