Unfolding now: news.ycombinator.com/item?id=3

- openwall.com/lists/oss-securit
- github.com/tukaani-project/xz/

An incredibly technically complex in xz (potentially also in libarchive and elsewhere) was just discovered. This backdoor has been quietly implemented over years, with the assistance of a wide array of subtly interconnected accounts:

- github.com/tukaani-project/xz/
- bugs.debian.org/cgi-bin/bugrep
- github.com/jamespfennell/xz/pu

The timeline on this is going to take so long to unravel

1
Share
Share on Mastodon
Share on Twitter
Share on Facebook
Share on Linkedin
Evan Boehs

boehs.org/node/everything-i-kn

I have begun a post explaining this situation in a more detailed writeup. This is updating in realtime, and there is a lot still missing.

#security #xz #linux

1
8mo
Replies