Arch isn't affected afaik, as it specifically targeted Debian and RPM. Also, sshd isn't linked against liblzma (or something along those lines). And I hope that's true, because otherwise, I had a backdoor on a public system for over a month.
this post was submitted on 30 Mar 2024
0 points (NaN% liked)
Memes
45546 readers
1290 users here now
Rules:
- Be civil and nice.
- Try not to excessively repost, as a rule of thumb, wait at least 2 months to do it if you have to.
founded 5 years ago
MODERATORS
And the packages on most distros should be long updated by now.
Even Termux updated to 5.6.1+really5.4.5
just 2 hours after Arch Linux.
I just updated all packages in Termux actually lol
What package manager is that?
Nala, Termux is Debian based and its pkg
is basically apt
And as https://www.openwall.com/lists/oss-security/2024/03/29/4 says:
"These conditions include targeting only x86-64 linux: [...] Building with gcc and the gnu linker [...] Running as part of a debian or RPM package build:"
I'm not an expert of course.