NetBSD Foundation 🚩 on Nostr: Regarding the XZ backdoor: NetBSD 8 -> xz 5.2.1, apparently unaffected NetBSD 9, 10, ...
Regarding the XZ backdoor:
NetBSD 8 -> xz 5.2.1, apparently unaffected
NetBSD 9, 10, current -> xz 5.2.4, apparently unaffected
stable pkgsrc -> xz 5.4.5, apparently unaffected
current pkgsrc -> affected.
Most NetBSD systems do _not_ use xz from pkgsrc. Update pkgsrc and replace the package if you have a custom configuration with --prefer-pkgsrc yes
Published at
2024-03-29 18:19:59Event JSON
{
"id": "79a708a7cefad1571f59a39631fb2b18ef3cea6ade5185db7a54568dccd830f6",
"pubkey": "40858d2dc9c0c8560f0b1e518843fbca59f886e28af7b79fc38dd88680a80633",
"created_at": 1711736399,
"kind": 1,
"tags": [
[
"proxy",
"https://mastodon.sdf.org/users/netbsd/statuses/112180356687992160",
"activitypub"
]
],
"content": "Regarding the XZ backdoor:\n\nNetBSD 8 -\u003e xz 5.2.1, apparently unaffected\nNetBSD 9, 10, current -\u003e xz 5.2.4, apparently unaffected\nstable pkgsrc -\u003e xz 5.4.5, apparently unaffected\ncurrent pkgsrc -\u003e affected.\n\nMost NetBSD systems do _not_ use xz from pkgsrc. Update pkgsrc and replace the package if you have a custom configuration with --prefer-pkgsrc yes",
"sig": "ed0130ab18f4fde2cb54bc51ef1bbf24ce2945059aea893808eff35eedde844aec4e1587e16a7a61e336ce1a80d721b2197138ab2b0e561e55a82485a8d55cfb"
}