What is Nostr?
Enno T. Boland /
npub1rrs…cxlm
2024-04-01 23:13:41

Enno T. Boland on Nostr: A thing I wasn't aware of: systemd switched to dlopen'ing compression libraries on ...

A thing I wasn't aware of: systemd switched to dlopen'ing compression libraries on demand, rendering the #xz attack useless with one of their next releases. That's why apparently the attackers tried to push distributions to include the new xz version on their stable releases before the mitigation in systemd was included.
Author Public Key
npub1rrsvngjhlz4fzcg7rgje73xaw9e5mpyjep2lqz7f6udmcp8e5m6syvcxlm