Skip to content

brew install xz installs the outdated version 5.4.6 instead of 5.6.1 #5243

Answered by Bo98
atncsj6h asked this question in Everyday usage
Discussion options

You must be logged in to vote

This is intentional as 5.6.x is untrusted: https://www.bleepingcomputer.com/news/security/red-hat-warns-of-backdoor-in-xz-tools-used-by-most-linux-distros/ (see https://www.openwall.com/lists/oss-security/2024/03/29/4 for technical details)

To be clear: we don't believe Homebrew's builds were compromised (the backdoor only applied to deb and rpm builds) but 5.6.x is being treated as no longer trustworthy and as a precaution we are forcing downgrades to 5.4.6.

Replies: 12 comments 30 replies

Comment options

You must be logged in to vote
12 replies
@christoofar
Comment options

@christoofar
Comment options

@adam-azarchs
Comment options

@p-linnane
Comment options

@p-linnane
Comment options

Answer selected by Bo98
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
11 replies
@Bo98
Comment options

Bo98 Mar 30, 2024
Maintainer

@Moulick
Comment options

@webfolderio
Comment options

@nevotheless
Comment options

@Crapshit
Comment options

Comment options

You must be logged in to vote
1 reply
@alexrecuenco
Comment options

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
3 replies
@porg
Comment options

@jazzilicious
Comment options

@p-linnane
Comment options

Comment options

You must be logged in to vote
1 reply
@Bo98
Comment options

Bo98 Apr 1, 2024
Maintainer

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
2 replies
@Bo98
Comment options

Bo98 Apr 4, 2024
Maintainer

@doodlesun
Comment options

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet