/?pid=24778

Updated:04:17 AM EST Mar 05


this is ggmania.com subsite Red Hat warns of backdoor in XZ tools used by most Linux distros - TechAmok

Red Hat warns of backdoor in XZ tools used by most Linux distros - [security]
06:23 AM EDT - Mar,30 2024 - post a comment

Today, Red Hat warned users to immediately stop using systems running Fedora development and experimental versions because of a backdoor found in the latest XZ Utils data compression tools and libraries.

"PLEASE IMMEDIATELY STOP USAGE OF ANY FEDORA 41 OR FEDORA RAWHIDE INSTANCES for work or personal activity," Red Hat warned on Friday.

"No versions of Red Hat Enterprise Linux (RHEL) are affected. We have reports and evidence of the injections successfully building in xz 5.6.x versions built for Debian unstable (Sid). Other distributions may also be affected."

Debian's security team also issued an advisory warning users about the issue. The advisory says that no stable Debian versions are using the compromised packages and that XZ has been reverted to the upstream 5.4.5 code on affected Debian testing, unstable, and experimental distributions.

Microsoft software engineer Andres Freund discovered the security issue while investigating slow SSH logins on a Linux box running Debian Sid (the rolling development version of the Debian distro).

However, he has not found the exact purpose of the malicious code added to XZ versions 5.6.0 and 5.6.1.

"I have not yet analyzed precisely what is being checked for in the injected code, to allow unauthorized access. Since this is running in a pre-authentication context, it seems likely to allow some form of access or other form of remote code execution," Freund said.  

"Initially starting sshd outside of systemd did not show the slowdown, despite the backdoor briefly getting invoked. This appears to be part of some countermeasures to make analysis harder."



Add your comment (free registrationrequired)

Short overview of recent news articles

Mar,05 2026 Google Drops Urgent Chrome Patch: 10 Flaws Fixed in Critical
Mar,05 2026 NVIDIA GeForce Hotfix Driver v595.76 is now available
Mar,04 2026 Google Slashes App Store Fees and Opens Door to Third-Party Stores
Mar,04 2026 Android's New Update Brings New Find My Features
Mar,04 2026 Samsung Confirms DRAM Prices Surge Over 100% in Q1 2026 Amid
Mar,04 2026 HW News - "Microslop" Censored, NVIDIA Unlaunches Drivers Again,
Mar,04 2026 A €55 ITX Case! - DeepCool CH170 DIGITAL Review
Mar,04 2026 Critical Flaw in MS-Agent AI Framework Exposes Systems to Remote
Mar,04 2026 South Korean Tax Officials Fumble $4.8 Million in Seized Crypto
Mar,03 2026 Windows 11 Upgrade Bug 'Deletes the Internet' for Some Users,
Mar,03 2026 Open-Source AI 'Hacker' Shannon Explodes to Fame with 96% Exploit
Mar,03 2026 Google Drops Massive Android Security Patch: Fixes 129 Flaws
Mar,02 2026 Apple Unveils iPhone 17e: MagSafe, A19 Chip, and Double Storage at
Mar,02 2026 NVIDIA GeForce 595.71 WHQL Driver
Mar,02 2026 Russian-Linked APT28 Exploits Zero-Day in Legacy MSHTML Engine to
Mar,02 2026 Honor Unveils Mind-Blowing Robot Phone with Dancing Camera at MWC
Mar,02 2026 Resident Evil 9 Requiem - Bonus DLC
Mar,01 2026 Microsoft's Copilot Discord Server Locked Amid 'Microslop' Spam
Mar,01 2026 Anghami CEO Open-Sources Powerful Real-Time Global War Monitor
Mar,01 2026 Chinese Developers Unleash Blazing-Fast Android AI Agent with
Mar,01 2026 Claude Surges to #1 on App Store as ChatGPT Faces Boycott Backlash
Feb,28 2026 Google Reveals Key New Features of Android 17
Feb,28 2026 OLED Gaming Monitors Are Finally Affordable
Feb,28 2026 OpenAI's KYC Partner Exposed in Surveillance Scandal as ChatGPT
Feb,28 2026 Pentagon Blacklists Anthropic Over AI Safeguards; OpenAI Secures
Feb,27 2026 Have RAM and GPU Prices Peaked?
Feb,27 2026 Zoom 'Update' Trap: Fake Site Infects 1,437 Users with Spyware in
Feb,27 2026 Stop WASTING Money on Fancy RAM
Feb,27 2026 Drunk AI robot
Feb,26 2026 AirSnitch Exposes Critical Flaw: Wi-Fi Client Isolation Broken in
Feb,26 2026 Revolutionary Ultrasonic Knife Hits Kitchens: C-200 Vibrates for
Feb,26 2026 Apple Scores Historic NATO Security Clearance: iPhone and iPad First
Feb,26 2026 Kali Linux Goes AI-Powered: Claude Now Runs Your Pen Tests in Plain
Feb,26 2026 Resident Evil Requiem - Stunning on PS5 Pro + PS5/Xbox Series X|S
Feb,26 2026 Samsung Galaxy S26 Ultra Flexes Hardware Muscle Over iPhone 17 Pro
Feb,26 2026 The Galaxy S26 Ultra has a 'wow' feature with video Lock
Feb,26 2026 I built the most BORING PC possible... and here is why it's
Feb,26 2026 Micron Blasts GDDR7 as Gaming Bottleneck While Nvidia's RTX 50
Feb,26 2026 UK Tightens Grip on Streaming Giants: Age Verification Now Mandatory
Feb,25 2026 Samsung Previews New AI Features Ahead of Flagship Phone Launch
>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs