this post was submitted on 30 Mar 2024
21 points (92.0% liked)

Monero

1662 readers
20 users here now

This is the lemmy community of Monero (XMR), a secure, private, untraceable currency that is open-source and freely available to all.

GitHub

StackExchange

Twitter

Wallets

Desktop (CLI, GUI)

Desktop (Feather)

Mac & Linux (Cake Wallet)

Web (MyMonero)

Android (Monerujo)

Android (MyMonero)

Android (Cake Wallet) / (Monero.com)

Android (Stack Wallet)

iOS (MyMonero)

iOS (Cake Wallet) / (Monero.com)

iOS (Stack Wallet)

iOS (Edge Wallet)

Instance tags for discoverability:

Monero, XMR, crypto, cryptocurrency

founded 1 year ago
MODERATORS
 

Urgent: serious backdoor impacts major linux distros Fedora, Kali, openSUSE, Debian

DegenRocket has summarized the info & given you a simple command to check if your Linux machine is vulnerable:

https://linked-out.me/news/55d3c9f25acde2d95282

top 7 comments
sorted by: hot top controversial new old
[–] [email protected] 6 points 7 months ago (2 children)

This is why I run good 'ol Debian Stable.

Slower is sometimes better. :-)

[–] [email protected] 2 points 7 months ago
[–] [email protected] 1 points 7 months ago (2 children)

This particular backdoor as far as anyone knows only affects Debian and derivatives and fedora. Arch ftw.

[–] [email protected] 3 points 7 months ago

yeah bro arch ftw... but you better update your rolling thing asap

[–] [email protected] 2 points 7 months ago

Actually, I had read that Arch is affected, and current advice was to update

https://archlinux.org/news/the-xz-package-has-been-backdoored/

You'll probably want to move up to 5.6.1-2 out of an abundance of caution, as recommended here https://security.archlinux.org/CVE-2024-3094

[–] [email protected] 1 points 7 months ago (1 children)

so you should check if you're running xz version 5.6.0 or 5.6.1

xz -V

[–] [email protected] 4 points 7 months ago

I read somewhere that you should avoid starting xz if you don't have to and therefore should use, for example,

apt-show-versions xz

(Though this has been two days ago and might not be relevant anymore, am not a dev).