programming.dev
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
starman to Nix / NixOSEnglish · 1 year ago

How the xz backdoor highlights a major flaw in Nix | Shade's Blog

shadeyg56.vercel.app

external-link
message-square
8
link
fedilink
  • cross-posted to:
  • [email protected]
35
external-link

How the xz backdoor highlights a major flaw in Nix | Shade's Blog

shadeyg56.vercel.app

starman to Nix / NixOSEnglish · 1 year ago
message-square
8
link
fedilink
  • cross-posted to:
  • [email protected]
Background On Friday, March 29th, 2024, a historical and sophisticated security vulnerability (CVE-2024-3094) was discovered in the XZ Utils package and liblzma api in version 5.6.0 and 5.6.1. While this vulnerability mostly affects Debian and RedHat distributions, there was some interesting discussion regarding xz and Nix. How did this affect Nix and NixOS? The truth is not a whole lot in reality. I saw conflicting reports, but supposedly, the tarballs of xz that Nix downloads were not infected.
  • GarlicToast
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    2
    ·
    edit-2
    6 months ago

    deleted by creator

Nix / NixOS

nix

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

Main links

  • website
  • wiki
  • matrix

Videos

  • Linux Experiment about NixOS
  • Chris Titus Tech
  • Mental Outlaw
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 4 users / day
  • 83 users / week
  • 161 users / month
  • 524 users / 6 months
  • 424 local subscribers
  • 2.39K subscribers
  • 260 Posts
  • 1.16K Comments
  • Modlog
  • mods:
  • Erlingur
  • ballmerpeaking
  • WhiteBlackGoose
  • BE: 0.19.11
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org