Should we be worried about the xz backdoor? #49614
Replies: 2 comments 3 replies
-
The Arch guys said this too here:
|
Beta Was this translation helpful? Give feedback.
-
void's sshd (or its dependencies) do not link against liblzma, so under the current knowledge, the attack is not possible. |
Beta Was this translation helpful? Give feedback.
-
As far as I know, Void Linux shouldn't be affected by this even if we are building xz & liblzma from the release tarballs (which we are), because according to Andres Freund here.
Right now Void is shipping version 5.6.0 (which is an affected version) with #49444 to bump it to 5.6.1. Should we downgrade?
Beta Was this translation helpful? Give feedback.
All reactions