All of lore.kernel.org
 help / color / mirror / Atom feed
* Backdoor in xz, should we switch compression format for tarballs?
@ 2024-03-29 17:59 Paolo Bonzini
  2024-03-29 18:33 ` Alex Bennée
                   ` (2 more replies)
  0 siblings, 3 replies; 6+ messages in thread
From: Paolo Bonzini @ 2024-03-29 17:59 UTC (permalink / raw)
  To: qemu-devel, Michael Roth, Maydell, Peter, P. Berrange, Daniel

[-- Attachment #1: Type: text/plain, Size: 304 bytes --]

For more info, see
https://lwn.net/ml/oss-security/20240329155126.kjjfduxw2yrlxgzm@awork3.anarazel.de/
but, essentially, xz was backdoored and it seems like upstream was directly
responsible for this.

Based on this, should we switch our distribution from bz2+xz to bz2+zstd or
bz2+lzip?

Thanks,

Paolo

[-- Attachment #2: Type: text/html, Size: 564 bytes --]

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2024-03-31  8:09 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2024-03-29 17:59 Backdoor in xz, should we switch compression format for tarballs? Paolo Bonzini
2024-03-29 18:33 ` Alex Bennée
2024-03-29 20:00 ` Daniel P. Berrangé
2024-03-29 20:34   ` Alex Bennée
2024-03-30 10:03 ` Stefan Hajnoczi
2024-03-31  8:07   ` Michael Tokarev

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.