-1 points

Bad title. This is CVE-2024-3094. Run “xz --version” to see if you are affected.

permalink
report
reply
82 points

“Run the affected binary to see if you have it”

permalink
report
parent
reply
7 points
*
Deleted by creator
permalink
report
parent
reply
3 points

Can’t you edit it?

permalink
report
parent
reply
1 point
*
Deleted by creator
permalink
report
parent
reply
65 points

AFAIK it‘s better to use rpm -q xz xz-libs (copied from the forum replies) to avoid running xz itself just in case the affected version is already installed

permalink
report
parent
reply
56 points

If you go to the post, on the comments, there is someone that is already telling you to run dnf list xz --installed. So you don’t need to run xz directly.

permalink
report
parent
reply
2 points

If you are checking out the extent of damage on your system do not use ldd to check the links.

You can inadvertently executed the exploit this way.

permalink
report
parent
reply
-6 points

USE WINDOWS.

permalink
report
reply
3 points

if this happened on windows probably no one would have noticed it until a large cyberattack happened, also, using that logic no one should be using CPU’s created after 1995 due to meltdown / spectre

permalink
report
parent
reply
-4 points

Hahaha irritating isn’t it?

permalink
report
parent
reply
2 points
*

Im not irritated, im saying that your logic is flawed, stop using some software piece due to a vulnerability is at least dumb, every software will have at least one, open source or not, we are humans, we commit errors, example: the SMB vulnerability that allowed the quick spread of WannaCry in 2017, and that was on Windows, and actually we are lucky that this happened on open source software and not in some big corporation privative software, if that was the case, we wouldnt be able to know about the backdoor until a large cyberattack happened

permalink
report
parent
reply
4 points
*
Deleted by creator
permalink
report
parent
reply
-3 points

Lol triggered.

permalink
report
parent
reply
0 points

“No you are wrong.” YoU aRe So tRiGgErEd! 🤓

Dumb dumb.

permalink
report
parent
reply
3 points
*

So far I was affected on termux. There is already package update.

permalink
report
reply
4 points

Running Ubuntu 23.10 with xz-utils 5.41 which is unaffected. Versions 5.6.0 and 5.6.1 are the malicious packages. I used Synaptic Package Manager to search for it.

permalink
report
reply
3 points

On Ubuntu the only affected people were those running the prerelease of Ubuntu 24.04 who had installed the update from the proposed pocket.

permalink
report
parent
reply
8 points

The bad actor had a launchpad bug to pull it into the Ubuntu LTS beta. Serious kudos to the person who discovered it, literally in the nick of time.

permalink
report
parent
reply
4 points

Same story with Fedora

permalink
report
parent
reply
11 points

I am looking at these gaggle of posts and all of lemmy is flooded with this and then think that there is an entire Spyware OS on the other side… Which who knows what code it runs and people are chill about it. I am so thankful for this community.

permalink
report
reply

Linux

!linux@lemmy.ml

Create post

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word “Linux” in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

  • Posts must be relevant to operating systems running the Linux kernel. GNU/Linux or otherwise.
  • No misinformation
  • No NSFW content
  • No hate speech, bigotry, etc

Related Communities

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

Community stats

  • 8.3K

    Monthly active users

  • 6.3K

    Posts

  • 173K

    Comments