A backdoor in xz
A backdoor in xz
Posted Mar 31, 2024 18:54 UTC (Sun) by Cyberax (✭ supporter ✭, #52523)In reply to: A backdoor in xz by nix
Parent article: A backdoor in xz
This is subject to change: https://lwn.net/Articles/958438/
> particularly when those changes *reduce* security
They don't. libsystemd will _still_ depend on xz, it just will be hidden from cursory analysis.
> What next? Shall we make changes to allow for Windows's per-libc malloc(),
That's actually a pretty good idea, that will make several classes of vulnerabilities more difficult to exploit.
> or for Linux's not-at-all-planned upcoming transition to Mach-O?
I'd take PE: https://blog.hiler.eu/win32-the-only-stable-abi/
