Audit xz
and libarchive
in dom0
etc due to being released by known-malicious individual
#9071
Labels
C: other
P: default
Priority: default. Default priority for new issues, to be replaced given sufficient information.
project management
This issue pertains to the management of the Qubes OS Project.
security
This issue pertains to the security of Qubes OS.
T: task
Type: task. An action item that is neither a bug nor an enhancement.
Originally posted by @marmarek in #9067 (comment)
xz-5.4.1 was released by the very same person who inserted the backdoor into 5.6.0/5.6.1:
https://github.com/tukaani-project/xz/tree/v5.4.1
We should look at libarchive too; vulnerabilities are now known to have been inserted by the same person who backdoored
xz
:libarchive/libarchive#1609
A good timeline is still being created here:
https://boehs.org/node/everything-i-know-about-the-xz-backdoor
We may wish to consider the use of zstd instead:
https://github.com/facebook/zstd
The text was updated successfully, but these errors were encountered: