Lemmy.one
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
starman@programming.dev to Nix / NixOS@programming.devEnglish · 2 years ago

How the xz backdoor highlights a major flaw in Nix | Shade's Blog

shadeyg56.vercel.app

external-link
message-square
8
fedilink
  • cross-posted to:
  • linux@lemmy.ml
40
external-link

How the xz backdoor highlights a major flaw in Nix | Shade's Blog

shadeyg56.vercel.app

starman@programming.dev to Nix / NixOS@programming.devEnglish · 2 years ago
message-square
8
fedilink
  • cross-posted to:
  • linux@lemmy.ml
Background On Friday, March 29th, 2024, a historical and sophisticated security vulnerability (CVE-2024-3094) was discovered in the XZ Utils package and liblzma api in version 5.6.0 and 5.6.1. While this vulnerability mostly affects Debian and RedHat distributions, there was some interesting discussion regarding xz and Nix. How did this affect Nix and NixOS? The truth is not a whole lot in reality. I saw conflicting reports, but supposedly, the tarballs of xz that Nix downloads were not infected.
  • starman@programming.devOP
    link
    fedilink
    English
    arrow-up
    6
    ·
    edit-2
    2 years ago

    That’s true, but you have to know there was a backdoor first. If someone doesn’t know, and they use the latest version, they’re vulnerable to attack

    • Dan MacLeod :PUA:@aus.social
      link
      fedilink
      arrow-up
      9
      ·
      2 years ago

      @starman @GarlicToast true but I don’t think you can use nix and not know about the xz exploit within minutes of it being found out.

      • onlinepersona@programming.dev
        link
        fedilink
        English
        arrow-up
        4
        ·
        2 years ago

        Do you have an RSS feed of CVEs impacting Nixos?

        Anti Commercial AI thingy

        CC BY-NC-SA 4.0

        • λλλ@programming.dev
          link
          fedilink
          English
          arrow-up
          2
          ·
          2 years ago

          I believe the point they were making is that if you are techy enough to use nix, they are likely the type to keep up to date with news like this.

    • GarlicToast@programming.dev
      link
      fedilink
      English
      arrow-up
      6
      ·
      edit-2
      1 year ago

      deleted by creator

    • pbsds@lemmy.ml
      link
      fedilink
      English
      arrow-up
      4
      ·
      2 years ago

      If the issue had been critical, then the branch head could be rolled back, causing everyone to downgrade

      • Atemu@lemmy.ml
        link
        fedilink
        English
        arrow-up
        2
        ·
        edit-2
        2 years ago

        That’s a nice idea in theory but not possible in practice as the last Nixpkgs revision without a tainted version of xz is many months old. You’d trade one CVE for dozens of others.

Nix / NixOS@programming.dev

nix@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !nix@programming.dev

Main links

  • website
  • wiki
  • matrix

Videos

  • Linux Experiment about NixOS
  • Chris Titus Tech
  • Mental Outlaw
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 12 users / day
  • 46 users / week
  • 129 users / month
  • 470 users / 6 months
  • 12 local subscribers
  • 2.72K subscribers
  • 360 Posts
  • 1.41K Comments
  • Modlog
  • mods:
  • Erlingur@programming.dev
  • ballmerpeaking@programming.dev
  • WhiteBlackGoose@programming.dev
  • BE: 0.19.7
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org