Fwd: XZ Utils 5.8.4 and a security fix
XZ Utils 5.8.4 fixes an invalid memory write that occurs when a decoder is reinitialized after allocation failure in 5.8.3 and older.
XZ Utils 5.8.4 has been released with a security fix for versions 5.8.3 and older. The flaw is an invalid memory write that can occur when a decoder is reinitialized after an allocation failure. The announcement was posted on the oss-security mailing list by Sam James pointing to the upstream stable release. Users and distributions running affected versions should upgrade to 5.8.4.
Backdoor Xz Utils Linux Open Source
Infosecurity Magazine covers the XZ Utils open-source backdoor, a malicious implant in liblzma that targeted OpenSSH on major Linux distributions.
The article covers the XZ Utils backdoor, a malicious implant introduced into the widely used open-source compression library. The compromised liblzma code manipulated functions used by OpenSSH, nearly reaching stable releases of major Linux distributions before discovery. The incident is a prominent example of software supply chain compromise targeting critical open-source infrastructure.