• qwioeue@lemmy.worldOP
    link
    fedilink
    arrow-up
    17
    arrow-down
    10
    ·
    edit-2
    3 months ago

    Yes, this sshd attack vector isn’t possible. However, they haven’t decomposed the exploit and we don’t know the extent of the attack. The reporter of the issue just scratched the surface. If you are using Arch, you should run pacman right now to downgrade.

    • Fubarberry@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      36
      ·
      3 months ago

      They actually have an upgrade fix for it, at least for the known parts of it. Doing a standard system upgrade will replace the xz package with one with the known backdoor removed.

    • HopFlop@discuss.tchncs.de
      link
      fedilink
      arrow-up
      15
      ·
      3 months ago

      If you are using Arch, you should run pacman right now to downgrade.

      No, just update. It’s already fixed. Thats the point of rolling release.