Replies: 2 comments 3 replies
-
|
The Arch guys said this too here:
|
Beta Was this translation helpful? Give feedback.
-
void's sshd (or its dependencies) do not link against liblzma, so under the current knowledge, the attack is not possible. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
As far as I know, Void Linux shouldn't be affected by this even if we are building xz & liblzma from the release tarballs (which we are), because according to Andres Freund here.
Right now Void is shipping version 5.6.0 (which is an affected version) with #49444 to bump it to 5.6.1. Should we downgrade?
Beta Was this translation helpful? Give feedback.
All reactions