A backdoor in xz
A backdoor in xz
Posted Mar 30, 2024 19:05 UTC (Sat) by andresfreund (subscriber, #69562)In reply to: A backdoor in xz by judas_iscariote
Parent article: A backdoor in xz
Afaict all the options for doing so were used in this case. The redirection happened just before the got was remapped read only.
I'm somewhat surprised that nobody called for glibc's rtld-audit infrastructure to be removed. That's really what made this attack possible despite relro. As far as I know, it's not used widely.
