[SOLVED]The xz package has been backdoored

This forum is for discussion about general software issues.

[SOLVED]The xz package has been backdoored

Postby m3 » Fri Mar 29, 2024 7:28 pm

According to archlinux today's news, xz package needs urgent update.

Current version is 5.6.1-1 and is compromised.

Any actions for update?

EDIT
xz 5.6.1-2 is now pushed to mirrors.
Kudos
Last edited by m3 on Sat Mar 30, 2024 4:44 am, edited 1 time in total.
m3
 
Posts: 5
Joined: Fri Mar 29, 2024 7:19 pm

Re: The xz package has been backdoored

Postby neildarlow » Fri Mar 29, 2024 9:18 pm

The package listing here shows the update as available but it hasn't reached the repositories yet. Can this be expedited? It's a very concerning vulnerability.

EDIT: Reading some background on this, the code-injection logic within the build seems to specifically target only the x86_64 architecture. This might give us some degree of safety but known, not vulnerable, version packages would be best for peace of mind.
neildarlow
 
Posts: 18
Joined: Fri Jul 17, 2020 10:45 am

xz has been backdoored, when do we expect an update on ARM?

Postby potuz » Fri Mar 29, 2024 9:27 pm

make_clickable_callback(MAGIC_URL_FULL, '', 'https://archlinux.org/news/the-xz-package-has-been-backdoored/', '', ' class="postlink"')

My just upgraded arch on ARM v7 still shows an affected version.
potuz
 
Posts: 4
Joined: Sat Mar 02, 2019 10:41 pm

Backdoored xz

Postby megabaseballdork » Fri Mar 29, 2024 9:27 pm

Hey, looks like xz 5.6.1-1 is still what's being shipped currently. Any ETA on a bump?

Background:
[url]https://archlinux.org/news/the-xz-package-has-been-backdoored/[/url]
megabaseballdork
 
Posts: 1
Joined: Sun Jun 18, 2023 10:04 pm

Re: The xz package has been backdoored

Postby mnot » Fri Mar 29, 2024 9:59 pm

5.6.1-2 is out, but I don't see it on the mirrors yet.
mnot
 
Posts: 3
Joined: Thu Jan 03, 2019 1:10 am

Re: [SOLVED]The xz package has been backdoored

Postby graysky » Sat Mar 30, 2024 5:24 am

MOD note: merged
graysky
Developer
 
Posts: 1876
Joined: Sun Jun 26, 2011 6:56 am
Location: /run/user/1000

Re: [SOLVED]The xz package has been backdoored

Postby graysky » Sat Mar 30, 2024 10:49 am

See allan's post:make_clickable_callback(MAGIC_URL_FULL, ' ', 'https://bbs.archlinux.org/viewtopic.php?pid=2160841#p2160841', '', ' class="postlink"')

[quote=Allan][quote=alvrogd][quote=seth]From what has been discovered so far this was a rather specific attack exploiting a downstream patch of sshd in debian and redhat.
I've not compared the binaries myself so I don't vouch for those findings but it's rather likely that your system has never been compromised tbw.[/quote]

I've followed the conversation in the original report, and found some users comparing Arch's xz 5.6.1-1 vs. 5.6.1-2. By disassembling the liblzma library, it appears that the packages might have never been affected by the backdoor, due to the deb/rpm check in the script that decides whether to inject the vulnerability or not.

References:

[url]https://www.openwall.com/lists/oss-security/2024/03/29/17[/url]
[url]https://www.openwall.com/lists/oss-security/2024/03/29/20[/url]
[url]https://www.openwall.com/lists/oss-security/2024/03/29/22[/url][/quote]


This is the important bit. There was not issue with Arch because the backdoor checked if xz was being built on an RPM or Deb based system before it was activated. The rebuild is purely precautionary, and completely unneeded.[/quote]
graysky
Developer
 
Posts: 1876
Joined: Sun Jun 26, 2011 6:56 am
Location: /run/user/1000

Re: [SOLVED]The xz package has been backdoored

Postby technosf » Sun Mar 31, 2024 9:53 pm

TY graysky!
[size=85] MochaBin 5G || NSA325 [/size]
technosf
 
Posts: 147
Joined: Sat Jan 08, 2011 10:54 pm


Return to General

Who is online

Users browsing this forum: No registered users and 14 guests

cron