programming.dev
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
starman to Nix / NixOSEnglish · 1 year ago

How the xz backdoor highlights a major flaw in Nix | Shade's Blog

shadeyg56.vercel.app

external-link
message-square
8
link
fedilink
  • cross-posted to:
  • [email protected]
35
external-link

How the xz backdoor highlights a major flaw in Nix | Shade's Blog

shadeyg56.vercel.app

starman to Nix / NixOSEnglish · 1 year ago
message-square
8
link
fedilink
  • cross-posted to:
  • [email protected]
Background On Friday, March 29th, 2024, a historical and sophisticated security vulnerability (CVE-2024-3094) was discovered in the XZ Utils package and liblzma api in version 5.6.0 and 5.6.1. While this vulnerability mostly affects Debian and RedHat distributions, there was some interesting discussion regarding xz and Nix. How did this affect Nix and NixOS? The truth is not a whole lot in reality. I saw conflicting reports, but supposedly, the tarballs of xz that Nix downloads were not infected.
  • Dan MacLeod :PUA: :fedora:@aus.social
    link
    fedilink
    arrow-up
    9
    arrow-down
    2
    ·
    1 year ago

    @starman @GarlicToast true but I don’t think you can use nix and not know about the xz exploit within minutes of it being found out.

    • onlinepersona
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      1
      ·
      1 year ago

      Do you have an RSS feed of CVEs impacting Nixos?

      Anti Commercial AI thingy

      CC BY-NC-SA 4.0

      • λλλ
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 year ago

        I believe the point they were making is that if you are techy enough to use nix, they are likely the type to keep up to date with news like this.

Nix / NixOS

nix

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

Main links

  • website
  • wiki
  • matrix

Videos

  • Linux Experiment about NixOS
  • Chris Titus Tech
  • Mental Outlaw
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 26 users / day
  • 34 users / week
  • 121 users / month
  • 496 users / 6 months
  • 405 local subscribers
  • 2.17K subscribers
  • 224 Posts
  • 1.01K Comments
  • Modlog
  • mods:
  • Erlingur
  • ballmerpeaking
  • WhiteBlackGoose
  • BE: 0.19.11
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org