From: Mark W. <ma...@kl...> - 2024-03-30 11:43:20
|
For those of you tracking the xz backdoor: https://lwn.net/Articles/967180/ valgrind plays a little role in the discovery. "Then recalled that I had seen an odd valgrind complaint in my automated testing of postgres, a few weeks earlier, after some package updates were installed." https://lwn.net/Articles/967194/ See also the attached email, which talks about this bug report: https://bugzilla.redhat.com/show_bug.cgi?id=2267598 So please always take valgrind memcheck errors seriously and investigate them! P.S. Sourceware isn't impacted by this xz backdoor: https://fosstodon.org/@sourceware/112180412918966168 But we did reset the buildbot containers of the affected distros. |