• HaraldvonBlauzahn@feddit.orgOP
    link
    fedilink
    arrow-up
    4
    ·
    edit-2
    15 hours ago

    Here is more info on this:

    https://lwn.net/SubscriberLink/1077035/c7e7c14fbd60fae9/

    (I hope sharing this link is OK, Linux Weekly News is high-quality, ad-free, and funds itself with subscriptions.)

    There exist speculations that this could be a clumsy attempt of an attack similar to xz-utils, where the project was taken over overworked maintainer by a malicious actor that inserted exploit code (well hidden in binary test data) which was triggered on distributions build servers.