Episode #968 Quiz
A Cautionary Tale
Date: 2024-04-02 | Length: 1.5 hrs | Episode page at twit.tv
About this episode
XZ Utils 5.6.0/5.6.1 hid a multi-year supply-chain backdoor that abused systemd-linked liblzma to alter sshd pre-authentication behavior, enabling remote RSA-keyed code execution with root privileges across Linux. Discovery came from anomalous SSH CPU use. Separately, Linux kernels 5.14–6.6.14 needed patching for a local privilege escalation bug.
Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.