* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Tuesday, August 26, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    ‘The Roses’ review: Olivia Colman, Benedict Cumberbatch sparkle in dark comedy – Yakima Herald-Republic

    The Roses’ Review: Olivia Colman and Benedict Cumberbatch Shine in Dark Comedy Delight

    ‘When Calls the Heart’ Fans All Want the Same Thing After Seeing the Show’s Latest Update – yahoo.com

    When Calls the Heart’ Fans Rally Together in Excitement Over Exciting New Update!

    Quotes of the Week: Peacemaker, Project Runway, Countdown and More – yahoo.com

    This Week’s Most Memorable Quotes from Peacemaker, Project Runway, Countdown, and More!

    Drake Appears in Teaser for Bobbi Althoff’s New Podcast ‘Not This Again’ – yahoo.com

    Drake Drops a Surprise Cameo in Bobbi Althoff’s Thrilling New Podcast Teaser ‘Not This Again

    From polka to Poison, Corn Palace adjusts entertainment offerings with the times – Mitchell Republic

    From polka to Poison, Corn Palace adjusts entertainment offerings with the times – Mitchell Republic

    How to watch ‘F1: The Movie’ on Prime Video – About Amazon

    Experience the Thrill: How to Stream ‘F1: The Movie’ on Prime Video

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    The Role of AI and Technology in Shaping the Future of Interactive Entertainment – Technology Org

    How AI and Technology Are Transforming the Future of Interactive Entertainment

    Ten upcoming sports stadiums where technology takes to the field – Dezeen

    10 Futuristic Sports Stadiums Revolutionizing the Game with Cutting-Edge Technology

    Figure Technology Solutions, Inc. Files Registration Statement for Proposed Initial Public Offering – Business Wire

    Figure Technology Solutions, Inc. Unveils Exciting Plans for Its Upcoming Initial Public Offering

    UNLV Responds to Workforce Need with Microcredential in Nuclear Technology – University of Nevada, Las Vegas | UNLV

    UNLV Unveils Cutting-Edge Microcredential Program to Fuel Growth in Nuclear Technology

    Why Technology Will Never Take Over Completely – Patheos

    Why Technology Will Never Completely Control Our Lives

    Alcorn State awarded grant to boost STEM with VR technology – WJTV

    Alcorn State Secures Grant to Transform STEM Education Through Cutting-Edge VR Technology

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    ‘The Roses’ review: Olivia Colman, Benedict Cumberbatch sparkle in dark comedy – Yakima Herald-Republic

    The Roses’ Review: Olivia Colman and Benedict Cumberbatch Shine in Dark Comedy Delight

    ‘When Calls the Heart’ Fans All Want the Same Thing After Seeing the Show’s Latest Update – yahoo.com

    When Calls the Heart’ Fans Rally Together in Excitement Over Exciting New Update!

    Quotes of the Week: Peacemaker, Project Runway, Countdown and More – yahoo.com

    This Week’s Most Memorable Quotes from Peacemaker, Project Runway, Countdown, and More!

    Drake Appears in Teaser for Bobbi Althoff’s New Podcast ‘Not This Again’ – yahoo.com

    Drake Drops a Surprise Cameo in Bobbi Althoff’s Thrilling New Podcast Teaser ‘Not This Again

    From polka to Poison, Corn Palace adjusts entertainment offerings with the times – Mitchell Republic

    From polka to Poison, Corn Palace adjusts entertainment offerings with the times – Mitchell Republic

    How to watch ‘F1: The Movie’ on Prime Video – About Amazon

    Experience the Thrill: How to Stream ‘F1: The Movie’ on Prime Video

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    The Role of AI and Technology in Shaping the Future of Interactive Entertainment – Technology Org

    How AI and Technology Are Transforming the Future of Interactive Entertainment

    Ten upcoming sports stadiums where technology takes to the field – Dezeen

    10 Futuristic Sports Stadiums Revolutionizing the Game with Cutting-Edge Technology

    Figure Technology Solutions, Inc. Files Registration Statement for Proposed Initial Public Offering – Business Wire

    Figure Technology Solutions, Inc. Unveils Exciting Plans for Its Upcoming Initial Public Offering

    UNLV Responds to Workforce Need with Microcredential in Nuclear Technology – University of Nevada, Las Vegas | UNLV

    UNLV Unveils Cutting-Edge Microcredential Program to Fuel Growth in Nuclear Technology

    Why Technology Will Never Take Over Completely – Patheos

    Why Technology Will Never Completely Control Our Lives

    Alcorn State awarded grant to boost STEM with VR technology – WJTV

    Alcorn State Secures Grant to Transform STEM Education Through Cutting-Edge VR Technology

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Malicious SSH backdoor sneaks into xz, Linux world’s data compression library

March 30, 2024
in Technology
Malicious SSH backdoor sneaks into xz, Linux world’s data compression library
Share on FacebookShare on Twitter

Red Hat on Friday warned that a malicious backdoor found in the widely used data compression software library xz may be present in instances of Fedora Linux 40 and in the Fedora Rawhide developer distribution.

The IT giant said the malicious code, which appears to provide remote backdoor access via OpenSSH and systemd at least, is present in xz 5.6.0 and 5.6.1. The vulnerability has been designated CVE-2024-3094. It is rated 10 out of 10 in CVSS severity.

Users of Fedora Linux 40 may have received 5.6.0, depending upon the timing of their system updates, according to Red Hat. And users of Fedora Rawhide, the current development version of what will become Fedora Linux 41, may have received 5.6.1. Fedora 40 and 41 have not been officially released yet; version 40 is due out next month.

Users of other Linux and OS distributions should check to see which version of the xz suite they have installed. The infected versions, 5.6.0 and 5.6.1, were released on February 24 and March 9, respectively, and may not been incorporated into too many people’s deployments.

This supply-chain compromise may have been caught early enough to prevent widespread exploitation, and it may only mainly affect bleeding-edge distros that picked up the latest xz versions right away.

Debian Unstable and Kali Linux have indicated they are, like Fedora, affected; all users should take action to identify and remove any backdoored builds of xz.

“PLEASE IMMEDIATELY STOP USAGE OF ANY FEDORA RAWHIDE INSTANCES for work or personal activity,” the IBM subsidiary’s advisory shouted from the rooftops today. “Fedora Rawhide will be reverted to xz-5.4.x shortly, and once that is done, Fedora Rawhide instances can safely be redeployed.”

Red Hat Enterprise Linux (RHEL) is not affected.

Easy-to-use make-me-root exploit lands for recent Linux kernels. Get patching

Open source software has its perks, but supply chain risks can’t be ignored

Sysadmins: Why not simply verify there’s no backdoor in every program you install, and thus avoid any cyber-drama?

CIOs largely believe their software supply chain is vulnerable

How ‘sleeper agent’ AI assistants can sabotage your code without you realizing

The malicious code in xz versions 5.6.0 and 5.6.1 has been obfuscated, Red Hat says, and is only fully present in the source code tarball. Second-stage artifacts within the Git repo get turned into malicious code through the M4 macro in the repo during the build process. The resulting poisoned xz library is unwittingly used by software, such as the operating system’s systemd, after the library has been distributed and installed. The malware appears to have been engineered to alter the operation of OpenSSH server daemons that employ the library via systemd.

“The resulting malicious build interferes with authentication in sshd via systemd,” Red Hat explains. “SSH is a commonly used protocol for connecting remotely to systems, and sshd is the service that allows access.”

This authentication interference has the potential to allow a miscreant to break sshd authentication and remotely gain unauthorized access to an affected system. In summary, the backdoor appears to work like this: Linux machines install the backdoored xz library – specifically, liblzma – and this dependency in turn is ultimately used in some way by the computer’s OpenSSH daemon. At that point, the poisoned xz library is able to meddle with the daemon, and potentially allow an unauthorized miscreant to log in remotely.

As Red Hat put it:

A post to the Openwall security mailing list by Andres Freund, PostgreSQL developer and commiter, explores the vulnerability in greater detail.

AI hallucinates software packages and devs download them

READ MORE

“The backdoor initially intercepts execution by replacing the ifunc resolvers crc32_resolve(), crc64_resolve() with different code, which calls _get_cpuid(), injected into the code (which previously would just be static inline functions). In xz 5.6.1 the backdoor was further obfuscated, removing symbol names,” Freund explains, with the caveat that he’s not a security researcher or reverse engineer.

Freund speculates that the code “seems likely to allow some form of access or other form of remote code execution.”

The account name associated with the offending commits, together with other details like the time those commits were made, has led to speculation that the author of the malicious code is a sophisticated attacker, possibly affiliated with a nation-state agency.

The US government’s Cybersecurity and Infrastructure Security Agency (CISA) has already issued an advisory here. ®

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : The Register – https://go.theregister.com/feed/www.theregister.com/2024/03/29/malicious_backdoor_xz/

Tags: backdoormalicioustechnology
Previous Post

Easy-to-use make-me-root exploit lands for recent Linux kernels. Get patching

Next Post

Sega grabs tech layoff baton and dumps couple hundred Euro staff

WA Ecology official testifies against repeal of ‘endangerment finding’ that allows for climate regulation – The Spokesman-Review

WA Ecology official testifies against repeal of ‘endangerment finding’ that allows for climate regulation – The Spokesman-Review

August 26, 2025
Bishop Kearney girls’ hockey team partners with UR Medicine for science-based training – 13wham.com

Bishop Kearney Girls’ Hockey Team Teams Up with UR Medicine for Cutting-Edge Science-Based Training

August 26, 2025
STEM camps offered at National Museum of Nuclear Science and History – KRQE

Discover Thrilling STEM Camps Now Open at the National Museum of Nuclear Science and History!

August 26, 2025
7 things people do when they care too much about what others think – VegOut

7 Signs You’re Caring Too Much About What Others Think

August 26, 2025
The Role of AI and Technology in Shaping the Future of Interactive Entertainment – Technology Org

How AI and Technology Are Transforming the Future of Interactive Entertainment

August 26, 2025
First look: ‘Whistle Blowers’ doc focuses on the crisis facing youth sports officials – NBC 5 Dallas-Fort Worth

Inside the Crisis Facing Youth Sports Officials: An Eye-Opening Look at ‘Whistle Blowers

August 26, 2025
South Carolina city selected to host 2027 Diamond Youth Baseball World Series – WRDW

South Carolina City Selected to Host the Exciting 2027 Diamond Youth Baseball World Series

August 25, 2025

Brazil’s low-voltage consumers could save 16% on power bills – Valor International

August 25, 2025
‘The Roses’ review: Olivia Colman, Benedict Cumberbatch sparkle in dark comedy – Yakima Herald-Republic

The Roses’ Review: Olivia Colman and Benedict Cumberbatch Shine in Dark Comedy Delight

August 25, 2025
Georgia lawmakers plan for federal cuts to already ‘underfunded’ public health services – Grice Connect

Georgia Lawmakers Prepare to Fight Federal Cuts Threatening Public Health Services

August 25, 2025

Categories

Archives

August 2025
MTWTFSS
 123
45678910
11121314151617
18192021222324
25262728293031
« Jul    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (790)
  • Economy (809)
  • Entertainment (21,689)
  • General (16,673)
  • Health (9,850)
  • Lifestyle (823)
  • News (22,149)
  • People (811)
  • Politics (818)
  • Science (16,020)
  • Sports (21,309)
  • Technology (15,791)
  • World (791)

Recent News

WA Ecology official testifies against repeal of ‘endangerment finding’ that allows for climate regulation – The Spokesman-Review

WA Ecology official testifies against repeal of ‘endangerment finding’ that allows for climate regulation – The Spokesman-Review

August 26, 2025
Bishop Kearney girls’ hockey team partners with UR Medicine for science-based training – 13wham.com

Bishop Kearney Girls’ Hockey Team Teams Up with UR Medicine for Cutting-Edge Science-Based Training

August 26, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version