Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerable xz Package in current Pacman Mirror List #7

Closed
cdestefano opened this issue Mar 30, 2024 · 3 comments
Closed

Vulnerable xz Package in current Pacman Mirror List #7

cdestefano opened this issue Mar 30, 2024 · 3 comments

Comments

@cdestefano
Copy link

A know backdoor was put into xz on versions of 5.6.0 and 5.6.1. I think I tracked it back to the right repo as the mirror list is pulling latest. The same site bytemark.co.uk has the updated version of 03-29-2024 at the time of opening this issue which should include 5.6.1-2. All versions of the image during the range of 02-24-2024 and 03-28-2024 are affected.

I confirmed from downstream privoxy-vpn that pacman -Q --info xz returns 5.6.1-1.

While right now archlinux isn't noted as impacted due to ssh implementation but ArchLinux is recommending updating immediately.

CVE-2024-3094 :
NIST
Red Hat

Sources:
ArchLinux
Upstream Report

@binhex
Copy link
Owner

binhex commented Mar 30, 2024

Thanks, i am currently performing a rebuild of the base image which i will check once done, if it looks ok then i will kick off all downstream builds.

@shanelord01
Copy link

Thanks, i am currently performing a rebuild of the base image which i will check once done, if it looks ok then i will kick off all downstream builds.

Awesome - thanks for that. Can I provide an update to the unRAID forums that are calling this out?
https://forums.unraid.net/topic/159952-mar-29-2024-xzliblzma-potential-compromise/

@binhex
Copy link
Owner

binhex commented Apr 3, 2024

The base image has been rebuilt and most of the subsequent images have also been rebuilt, the reason not all have rebuilt is due to an srm64 unrelated issue, sadly I ran out of time as I'm on holiday now, but I shall take another look at this and finish off the build of the other images.

Please do keep in mind the risk here is next to zero, systemd is non operational, openssh is not installed in any of my images and arch was not susceptible to the attack.

@binhex binhex closed this as completed May 7, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants