• kaleissin
    arrow-up
    33
    arrow-down
    34
    ·
    7 months ago
    link
    fedilink

    Bad title. This is CVE-2024-3094. Run “xz --version” to see if you are affected.

    • ryannathans
      arrow-up
      83
      arrow-down
      1
      ·
      7 months ago
      link
      fedilink

      “Run the affected binary to see if you have it”

    • 1henno1
      arrow-up
      65
      arrow-down
      0
      ·
      7 months ago
      link
      fedilink

      AFAIK it‘s better to use rpm -q xz xz-libs (copied from the forum replies) to avoid running xz itself just in case the affected version is already installed

    • ⲇⲅⲇ
      arrow-up
      56
      arrow-down
      0
      ·
      7 months ago
      link
      fedilink

      If you go to the post, on the comments, there is someone that is already telling you to run dnf list xz --installed. So you don’t need to run xz directly.

    • bitwolf
      arrow-up
      2
      arrow-down
      0
      ·
      7 months ago
      link
      fedilink

      If you are checking out the extent of damage on your system do not use ldd to check the links.

      You can inadvertently executed the exploit this way.