Hacker News new | past | comments | ask | show | jobs | submit login

It seems like based on the (very well written) analysis that this is a way to bypass ssh auth, not something that phones out which would've been even scarier.

My server runs arch w/ a LTS kernel (which sounds dumb on the surface, but was by far the easiest way to do ZFS on Linux that wasn't Ubuntu) and it seems that since I don't have SSH exposed to the outside internet for good reason, and my understanding is Arch never patched shhd to begin with that I and most people who would be in similar situations to me are unaffected.

Still insane that this happened to begin with, and I feel bad for the Archlinux maintainers who are now going to feel more pressure to try to catch things like this.




Being included via libsystemd isn't the only way ssh can load liblzma, it can come as an indirect dependency of Selinux (and its PAM stack) IIUC. Which makes it even a bit more funny (?) since Arch also doesn't officially support any Selinux stuff.

There might be other ways sshd might pull in lzma, but those are the 2 ways I saw commonly mentioned.

On a different note, pacman/makepkg got the ability to checksum source repository checkouts in 6.1.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: