#liblzma
Overall the unnecessary source code and bundled libraries were substantial, but the biggest component was the out of control GCC debugging symbols, which are particularly bloated for the style of code generated by Cython. I considered ‑g1 but other Cython projects that control this mostly use ‑g0.
September 16, 2026 at 8:51 PM
1/6

Latest Slackware current update:

84 updates. Including a (* Security fix *)!

Thu Sep 10 00:16:15 UTC 2026
a/xz-5.8.4-x86_64-1.txz: Upgraded.
This update fixes a security issue:
liblzma: lzma_alone_decoder(), lzma_lzip_decoder(), lzma_auto_decoder(),
September 10, 2026 at 2:01 AM
xz/liblzma backdoor sat in plain sight on GitHub for months before nearly hitting production Linux distros. Open source maintainers are unpaid and burnt out. Nobody's watching the supply chain. That's how the attack surface expands.

The waitlist is live
morbiz.ai/marketing-engine
September 7, 2026 at 9:15 PM
Shlyakhtun, Gryzlov, Kukharenko, Nesterov, Vasiliev, Ziborov, Zolotarev, Pokras: Agent-Driven Verification of Memory Safety for liblzma Decoder Components with VST https://arxiv.org/abs/2608.29716 https://arxiv.org/pdf/2608.29716 https://arxiv.org/html/2608.29716
September 1, 2026 at 6:44 AM
the xz/liblzma backdoor sat in open source for months because code review is security theater. the real lesson: constraints that force simplicity, small codebases, minimal dependencies, read-only defaults, catch malice faster than checklists. the waitlist is live at morbiz.ai/marketing-engine
August 12, 2026 at 9:15 PM
🚨 EUVD-2024-31700
📊 10.0/10

📝 Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0.
Through a series of complex obfuscations, the liblzma build process ex...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-31700

#cybersecurity #infosec #cve #euvd
August 4, 2026 at 7:01 AM
broski 5 years ago this would have taken me 2 years to fix and made me grow as a person and as a developer to fix
July 24, 2026 at 12:39 AM
the xz/liblzma backdoor spread not because it was brilliant, but because a burned-out open-source dev accepted help from someone patient. the lesson isn't "audit harder." it's that you can't security-harden your way out of burnout. the waitlist is live morbiz.ai/marketing-engine
July 19, 2026 at 9:15 PM
2/
Andres Freund, a Microsoft engineer, noticed SSH logins taking ~500ms longer than they should.

Most people would shrug. He went digging instead.

He traced the delay into liblzma and found a backdoor in XZ Utils, a package shipped with nearly every Linux distribution.
June 11, 2026 at 6:31 AM
March 29. Microsoft engineer Andres Freund is benchmarking PostgreSQL.

Notices SSH using too much CPU. Profiles it. CPU time in liblzma inside sshd.

"It felt surreal. I wondered if I was having fever dreams."

He publishes. The internet catches fire.
April 3, 2026 at 4:08 PM
Bedrijven moeten geld verdienen, tenzij je met 100 % community projecten werkt en zelfs dan krijg je deze ellende.

https://www.ssh.com/blog/a-recap-of-the-openssh-and-xz-liblzma-incident
March 25, 2026 at 8:59 PM
Heb daar een razend interessante debriefing van 3 uur over gekregen. Er is twee jaar aan die attack gewerkt, en als Andres een leven had gehad in plaats van uit te zoeken waar een paar milliseconden vertraging van dan kwam … Al 7 jaar geen begrip meer voor zwarte IT.
www.ssh.com/blog/a-recap...
A recap of the OpenSSH and XZ/liblzma incident | SSH
A novel open source backdoor (CVE-2024-3094) was recently discovered from a widely used xz-utils 'liblzma' data compression library build system.
www.ssh.com
March 23, 2026 at 8:12 PM
The XZ Backdoor (CVE-2024–3094): How a Supply Chain Attack Nearly Compromised Every Linux Server A breakdown of CVE-2024–3094, how the attacker hijacked liblzma, and why this almost became the ...

#threat-intelligence #information-security #linux #cybersecurity #supply-chain

Origin | Interest […]
Original post on systemweakness.com
systemweakness.com
March 2, 2026 at 4:56 PM
They are, like many other foundational libraries, not “supposed to change much” (but may still need someone to take responsibility for occasional maintenance).
Techies vs spies: the xz backdoor debate
Diving into the dynamics of the brazen ploy to subvert the liblzma compression library.
lcamtuf.substack.com
February 24, 2026 at 7:12 PM
2024-03

CVE-2024-3094: хтось намагався додати бекдор у openssh через liblzma. Найцікавіше поки те, що у коді репозиторію немає, а у артефактах (архівах для завантаження) на github є. Принаймні, були до закривання.
February 22, 2026 at 6:04 PM
Nuevo episodio: En el mundo interconectado de hoy, la seguridad digital es más importante que nunca. Nos encontramos con la historia de una vulnerabilidad crítica que casi sacudió la infraestructura digital ... JeiJoLand.com
JlA 7x54 Un ciberataque que puso al descubierto la fragilidad del código abierto by Juego, luego aprendo
En el mundo interconectado de hoy, la seguridad digital es más importante que nunca. Nos encontramos con la historia de una vulnerabilidad crítica que casi sacudió la infraestructura digital del mundo entero. El protagonista de este relato es un componente de software aparentemente inocente: una biblioteca de compresión conocida como liblzma, parte del paquete XZ Utils. Aunque suene algo técnico, esta libra de compresión es nada menos que un engranaje crucial en el funcionamiento de OpenSSH, una herramienta ampliamente usada para conexiones remotas. Ahora, ¿cómo se convierte una simple libra de compresión en la estrella de una tragedia informática? Un hábil atacante logró eventualmente introducir una puerta trasera en liblzma. Pero no lo hizo de la noche a la mañana, no señor. El atacant consiguió ganar la confianza del único responsable de mantener este proyecto, un voluntario, durante nada menos que dos años y medio. La idea era simple y retorcida: inyectar código malicioso que comprometiera la seguridad desde las sombras.Afortunadamente, el clon de Sherlock Holmes en esta historia es un ingeniero con un ojo para los detalles. Se dio cuenta de un leve retraso en las conexiones, un síntoma tan pequeño pero tan revelador. Es como oír un crujido en una casa silenciosa: algunos lo ignoran, pero los más curiosos investigan. Este buscador de misterios digitales descubrió la vulnerabilidad antes de que diese su gran salto a las versiones estables de los sistemas Linux, evitando lo que podría haber sido una verdadera danza del caos cibernético.Este suceso pone de manifiesto una lección fundamental: la fragilidad de depender de proyectos de código abierto mantenidos por personas desinteresadas, pero cuya labor es crucial. La comunidad de código abierto es tan fuerte como sus eslabones más pequeños, y a veces, esos eslabones son sostenidos por un solo par de manos.Para poner en práctica lo aprendido, ¿por qué no organizar un juego de rol en el que los participantes sean parte de un equipo de seguridad informática? Se trata de resolver desafíos, descubrir vulnerabilidades ocultas y proteger infraestructuras digitales, todo mientras compiten por ver quién es el mejor detective cibernético.Si os apasionan las historias de espías digitales y queréis entender cómo podemos aprender jugando, os animamos a visitar JeiJoLand, donde el aprendizaje es siempre un juego. Vamos juntos a explorar el mundo de las posibilidades que el juego nos ofrece.
f.mtr.cool
February 2, 2026 at 5:19 PM
fuse-archive を最新に

$ fuse-archive --version
fuse-archive version: 1.17
libarchive version: libarchive 3.7.4
bzlib version: 1.0.8, 13-Jul-2019
liblz4 version: 1.10.0
liblzma version: 5.8.1
libzstd version: 1.5.7
zlib version: 1.3.1
FUSE library version 3.17.4
using FUSE kernel interface version 7 […]
Original post on inari.opencocon.org
inari.opencocon.org
December 4, 2025 at 11:27 AM
I've hit the "sunk cost fallacy" phase of waiting for liblzma to source build. Is something wrong with my depgraph? Probably. Am I going to stop and fix it? No.
November 7, 2025 at 10:32 PM
This repository demonstrates CVE-2024-3094, the backdoor discovered in xz utils versions 5.6.0+

It provides a Docker container with the vulnerable Debian package and a patched liblzma library to reproduce the SSH authentication bypass exploit

➤ https://ku.bz/4K_lDB_ff
October 5, 2025 at 6:06 PM
This repository demonstrates CVE-2024-3094, the backdoor discovered in xz utils versions 5.6.0+

It provides a Docker container with the vulnerable Debian package and a patched liblzma library to reproduce the SSH authentication bypass exploit

➜ https://ku.bz/4K_lDB_ff
September 5, 2025 at 6:06 PM
No, no one is forcing them, but maintainers get attached to their projects. They want to see the projects succeed. Here's the worst case of what happens today:

robmensching.com/blog/posts/2...
A Microcosm of the interactions in Open Source projects | RobMensching.com
Originally a thread on Twitter about the xz/liblzma vulnerability, when I finished typing it, I realized I had a real world slice of Open Source interaction that deserved more attention.
robmensching.com
August 21, 2025 at 5:18 PM
🎥 Nowe nagranie z XIV P.I.W.O.

➡️ „Poisoning your supply chain - the xz-utils SSH backdoor” – Łukasz Kędziora (Antmicro)

Prezentacja omawia głośny przypadek tylnej furtki w bibliotece liblzma, której celem było przejęcie kontroli nad OpenSSH.

👉 PeerTube […]

[Original post on fosstodon.org]
August 21, 2025 at 2:06 PM
liblzma (0.4.3)
lib.rs
August 18, 2025 at 12:52 AM