Elektrine lite

← Feed

@tragivictoria@mastodon.catgirl.cloud

Post #3276439

2026-04-29 15:53 UTC

@vwbusguy@mastodon.online @bookwar@floss.social Why? Distro packagers didn't discovered the vulnerability, but some random people. Distros, as always, just happily bumped the version without checking anything.

Replies (1)

  • @bookwar@floss.social 2026-04-29 16:18

    @tragivictoria@mastodon.catgirl.cloud It was literally reported through the distro security communication channels because the upstream was compromised and the "random person" relied on distro to handle it. "Given the apparent upstream involvement I have not reported an upstream bug. As I initially thought it was a debian specific issue, I sent a more preliminary report to security@...ian.org. Subsequently I reported the issue to distros@. CISA was notified by a distribution." https://www.openwall.com/lists/oss-security/2024/03/29/4 @vwbusguy@mastodon.online

    Open ##3276440