this post was submitted on 29 Mar 2024
401 points (99.0% liked)

Linux

48287 readers
627 users here now

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

Related Communities

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] delirious_owl@discuss.online 14 points 7 months ago (4 children)

What is the name of the software that is affected??

[–] milicent_bystandr@lemm.ee 15 points 7 months ago (1 children)

xz is the compromised package, but it in turn compromises ssh authentication

[–] Synnr@sopuli.xyz 20 points 7 months ago* (last edited 7 months ago) (1 children)

In turn it ~~compromises ssh authentication~~ allows remote code execution via system(); if the connecting SSH certificate contains the backdoor key. No user account required. Nothing logged anywhere you'd expect. Full root code execution.

https://news.ycombinator.com/item?id=39877312

There is also a killswitch hard-coded into it, so it doesn't affect machines of whatever state actor developed it.

https://news.ycombinator.com/item?id=39881018

It's pretty clear this is a state actor, targeting a dependency of one of the most widely used system control software on Linux systems. There are likely tens or hundreds of other actors doing the exact same thing. This one was detected purely by chance, as it wasn't even in the code for ssh.

If people ever wonder how cyber warfare could potentially cause a massive blackout and communications system interruption - this is how.

[–] afterthoughts@lemmy.ca 1 points 7 months ago (1 children)

tens of hundreds

You mean thousands?

[–] Synnr@sopuli.xyz 2 points 7 months ago

That was supposed to be or, not of.

[–] MadBigote@lemmy.world -3 points 7 months ago

Microsoft Edge.