URGENT! XZ pkg compromized

Will an update via Garuda Update be forthcoming?

@Colin if you are up to date, you are already on the “safe” version. Note that the desired version is a “-2”, as in “5.6.1-2” (not to be mistaken for “5.6.2”).

pacman -Q xz
xz 5.6.1-2

You can also rest assured that your system is not vulnerable to the known exploit, no matter what version is in use. Arch Linux - News: The xz package has been backdoored

7 Likes

I’m up to date:

pacman -Q xz
xz 5.6.1-2

Thanks for the info.

:smiling_face:

This is a valid point…

4 Likes

There was a new update, we should be extra safe now, I presume :slight_smile:

pacman -Q xz
xz 5.6.1-3
4 Likes

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.