23
top 4 comments
sorted by: hot top controversial new old
[-] infeeeee@lemm.ee 9 points 3 months ago* (last edited 3 months ago)

The CVE-2024-6409 vulnerability affects only the sshd server shipped in RHEL 9, while the upstream versions of sshd are not impacted.

Yes, only RHEL based releases affected (source):

Specifically, openssh-7.6p1-audit.patch found in Red Hat's package of OpenSSH adds code to cleanup_exit() that exposes the issue. Relevantly, this patch is found in RHEL 9 (and its rebuild/downstream distributions), where the package is based on OpenSSH 8.7p1.

Debian oldstable is safe from this as well

[-] sugar_in_your_tea@sh.itjust.works 3 points 3 months ago

Looks like openSUSE Leap is fine, not sure about other SUSE distros.

[-] devilish666@lemmy.world -4 points 3 months ago

Flashback xz package in linux getting louder and louder

[-] infeeeee@lemm.ee 8 points 3 months ago

xz was a deliberate supply chain attack this is just a bug, accidental, not a rhel backdoor

this post was submitted on 11 Jul 2024
23 points (100.0% liked)

Cybersecurity

5558 readers
124 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !cybersecurity@lemmy.capebreton.social !securitynews@infosec.pub !netsec@links.hackliberty.org !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 1 year ago
MODERATORS