WARNING: Malicious code in current pre-release & testing versions/variants: F40 and rawhide affected - users of F40/rawhide need to respond

⸻ Ban DHMO 🇦🇺 ⸻@aussie.zone to Linux@lemmy.ml – 401 points –
WARNING: Malicious code in current pre-release & testing versions/variants: F40 and rawhide affected - users of F40/rawhide need to respond
discussion.fedoraproject.org
74

You are viewing a single comment

I'm on Void, and I had the malicious version installed. Updating the system downgraded xz to 5.4.6, so it seems they are on it. I'll be watching discussions to decide if my system might still be compromised.

Did you have SSH open to the internet?

No, this is just my personal laptop. I don't even have access to an IP address I could enable port-forwarding on.

@Auli @56_ I have SSH open on internet… on ipv6, I’m safe. Do you think VPN open on the internet is safer ? (Think twice CVE-2024-21762…)

I would nuke it and rebuild. If nothing else it is a good test of backups