@dalias @carnage4life Rich, if you say that, it's probably true. Can you expand a little on why you think so? It's a honest question, I'm trying to understand
Notices by Giovanni Gherdovich (ggherdov@fosstodon.org)
-
Embed this notice
Giovanni Gherdovich (ggherdov@fosstodon.org)'s status on Sunday, 07-Apr-2024 21:07:08 JST Giovanni Gherdovich -
Embed this notice
Giovanni Gherdovich (ggherdov@fosstodon.org)'s status on Sunday, 07-Apr-2024 21:07:06 JST Giovanni Gherdovich @dalias @carnage4life I see. Makes sense. Indeed Red Hat/Fedora caught it already on March 4th running valgrind, only the attacker managed to bamboozle them arguing there was nothing to see. Attacker then upgraded the malware to 5.6.1.
https://bugzilla.redhat.com/show_bug.cgi?id=2267598 "Invalid writes regression in liblzma.so" You can't get away with such shenanigans forever.