17:48:35 jperkin: xz was compromized: https://www.openwall.com/lists/oss-security/2024/03/29/4, v5.6.0 ist in trunk :-( 18:41:15 xz was downgrade to 5.4.6: https://pkgsrc.se/archivers/xz 18:44:11 jfqd1: jperkin is aware, and there's a Mastodon toot about it (and SmartOS): 18:45:27 https://hostux.social/@smartosorg/112180279555414961 18:45:44 danmc: didnt saw the toot, will take a look now, thx for pointing it out! 18:46:16 jfqd1: Only trunk is affected, and builds are in progress for the downgrades (some are already done and published) 18:48:05 bahamat: yeah saw the one for i386, waiting for x86_64 18:49:05 Yeah, that one should be soon, I think. The mac ones take much longer, unfortunately. 18:51:18 In OmniOS, we are initially taking the same path as Arch and using the github-generated archive and generating all of the autoconf files ourselves. The problem is that there is no obvious "safe" downgrade target as they have all been released and signed by the same person back as far as 5.4.3 18:52:06 We are not vulnerable anyway (and the binaries from this new process match the old, which confirms that) since we fail all of the checks that the exploit performs - not debian/rpm, not linux, not GNU ld etc. 18:52:56 * not vulnerable to /this/ explicit exploit, it's possible there are more.. 19:05:45 i've seen (it's on the internet, so it must be true :P) that the same person might have also contributed to other projects as well... 19:06:18 so i guess we'll find out if there's anything else impacted 19:07:17 The pkgsrc decision is interesting - if downgrading, I think the only version I'd pick is 5.4.2 19:16:33 jbk: and it seems that this person put effords into to get it widly deployed: https://news.ycombinator.com/item?id=39866275 19:23:15 v5.4.3 seem to be the latest release signed not by this person. 19:24:35 s/latest/last/ 19:25:52 5.4.3 was signed by this person - https://github.com/tukaani-project/xz/releases/tag/v5.4.3 20:05:57 andyf: yes, you are right! 20:53:43 did you track the history to see 5.4.3 signer did not pull from the suspicious stuff? (rhetorical)