SDF Chatter
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
starman@programming.dev to Nix / NixOS@programming.devEnglish · 1 year ago

How the xz backdoor highlights a major flaw in Nix | Shade's Blog

shadeyg56.vercel.app

external-link
message-square
8
fedilink
  • cross-posted to:
  • linux@lemmy.ml
35
external-link

How the xz backdoor highlights a major flaw in Nix | Shade's Blog

shadeyg56.vercel.app

starman@programming.dev to Nix / NixOS@programming.devEnglish · 1 year ago
message-square
8
fedilink
  • cross-posted to:
  • linux@lemmy.ml
Background On Friday, March 29th, 2024, a historical and sophisticated security vulnerability (CVE-2024-3094) was discovered in the XZ Utils package and liblzma api in version 5.6.0 and 5.6.1. While this vulnerability mostly affects Debian and RedHat distributions, there was some interesting discussion regarding xz and Nix. How did this affect Nix and NixOS? The truth is not a whole lot in reality. I saw conflicting reports, but supposedly, the tarballs of xz that Nix downloads were not infected.
  • GarlicToast@programming.dev
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    2
    ·
    edit-2
    3 months ago

    deleted by creator

Nix / NixOS@programming.dev

nix@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !nix@programming.dev

Main links

  • website
  • wiki
  • matrix

Videos

  • Linux Experiment about NixOS
  • Chris Titus Tech
  • Mental Outlaw
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 3 users / day
  • 55 users / week
  • 190 users / month
  • 485 users / 6 months
  • 44 local subscribers
  • 2.24K subscribers
  • 234 Posts
  • 1.06K Comments
  • Modlog
  • mods:
  • Erlingur@programming.dev
  • ballmerpeaking@programming.dev
  • WhiteBlackGoose@programming.dev
  • BE: 0.19.8
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org