XCP-ng
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    XZ Backdoor for SSH

    Scheduled Pinned Locked Moved Management
    5 Posts 3 Posters 414 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      axel
      last edited by

      Hello

      Ther is a backdoor (by a "bond?" or other spys ?) in liblzma. This is loade by ssh. this backdoor allow code injection by a "wrong" crypt key. It is a supply chain attac tooooo..

      https://www.helpnetsecurity.com/2024/03/31/xz-backdoored-linux-affected-distros/

      Did we need a hotfix or workaround or quick update (roolback) in xcp ?

      thx Axel

      1 Reply Last reply Reply Quote 0
      • olivierlambertO Offline
        olivierlambert Vates 🪐 Co-Founder CEO
        last edited by

        Hi,

        XCP-ng is not affected at all by this issue 🙂

        1 Reply Last reply Reply Quote 0
        • bleaderB Offline
          bleader Vates 🪐 XCP-ng Team
          last edited by

          I'll investigate this further today to be a 100% sure, but the version of XZ we have is not impacted, plus we build from a copied tarball in our build system, so even if the tarball of this version was impacted later than the time we downloaded the tarball we would not be impacted.

          We'll make a communication about it once I finished double checking it.

          1 Reply Last reply Reply Quote 1
          • bleaderB Offline
            bleader Vates 🪐 XCP-ng Team
            last edited by

            My bad, forgot this was a package we took from CentOS 7, but this package was made prior to JiaT75 starting this journey.

            For reference:

            • timeline
            • visual version
            A 1 Reply Last reply Reply Quote 0
            • A Offline
              axel @bleader
              last edited by

              @bleader Thx for your answer 🙂 and good to know 🙂

              1 Reply Last reply Reply Quote 0
              • First post
                Last post