Well this is fucking lovely....
Malicious code was discovered in the upstream tarballs of "xz" which then affects liblzma
Downstream there may be backdoors in various implementations of "sshd".
Versions Affected:
- Fedora 41
- Fedora Rawhide
- openSUSE Tumbleweed
- Debian testing, unstable, experimental distributions
- Kali updates between March 26th and March 29th
Original notice here:
https://www.openwall.com/lists/oss-security/2024/03/29/4
Red Hat CVE: https://nvd.nist.gov/vuln/detail/CVE-2024-3094
Red Hat Security Blog Post: https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users
Arch Linux Security Post:
... show moreRed Hat Information Risk and Security and Red Hat Product Security learned that the latest versions of the “xz” tools and libraries contain malicious code that appears to be intended to allow unauthorized access.
, (Red Hat)