XZ Gets the All-Clear

Apr 15, 2024

The back door xz vulnerability has been officially reverted for Fedora 40 and versions 38 and 39 were never affected.

If you've been in panic mode over the xz backdoor vulnerability, fret not as it has been patched for Fedora 40 beta and Rawhide.

According to Fedora Magazine, if you applied an update to the beta or rawhide versions during the time when the compromised package was found in its repositories, the current update is now reverted, so version 5.4.6 should be installed.

Fedora Magazine also goes on to mention that the SSH daemon doesn't run by default, so the Workstation edition is even less at risk.

On the Ubuntu side of things, Canonical delayed the final release of Noble Numbat (version 24.04) until April 25 so they could address the problem.

Red Hat Enterprise Linux, stable Debian releases, Linux Mint, Gentoo Linux, Alpine Linux, and Amazon Linux are uaffected by the xz flaw.

As for Arch Linux, the maintainers have created this page to help users. The page includes a recent update that states, "To our knowledge, the malicious code which was distributed via the release tarball never made it into the Arch Linux provided binaries, as the build script was configured to only inject the bad code in Debian/Fedora based package build environments. The news item below can therefore mostly be ignored."

Fortunately, xz was discovered before any serious damage could occur and should serve as a cautionary tale for development teams around the globe.
 
 
 

 
 
 

Related content

  • GNOME 41 Has Arrived

    The latest version of the GNOME desktop environment has been released with new functionality and plenty of improvements.

  • Goddard in the Starting Blocks: Course set for Fedora 13

    Following last weeks feature freeze, the Fedora team yesterday branched Fedora 13 away from the main developer repository "Rawhide."

  • News

    TUXEDO Computers Unveils Linux Laptop Featuring AMD Ryzen CPU; XZ Utils Vulnerability Patched; Canonical Collaborates with Qualcommon New Venture; Kodi 21.0 Entertainment Hub Released; Linux Usage Increases in Two Key Areas; Canonical Bumps LTS Support to 12 Years; Fedora 40 Beta Released; SnoopGod to Compete with Kali Linux; Juno Computers Launches Neptune 17 v6; and Juno Computers Launches Neptune 17 v6.

  • News

    In the news: Linux Now Runs on Apple's M1 Chipset; MX Linux 21 RC Now Available; Fedora 35 Improves Desktop Performance; Extended Support for Ubuntu 14.04 and 16.04; Gnome 41 Adds Desktop Improvements; and Black Lotus Labs Confirms Flaw in Windows Subsystem for Linux.

  • Arch-Based blendOS Features Cool Trick

    If you're looking for a Linux distribution that blends Linux, Android, and web apps together, blendOS might be what you're looking for.

comments powered by Disqus
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Subscribe to our ADMIN Newsletters

Support Our Work

Linux Magazine content is made possible with support from readers like you. Please consider contributing when you’ve found an article to be beneficial.

Learn More

News