@AndresFreundTec@mastodon.social
Post #4241053
2024-03-29 21:01 UTC
@noahm@chaos.social @corbet@social.kernel.org The vulnerable version was already present in debian test/unstable before that, it was just 5.6.0 instead of 5.6.1. And it was uploaded by the in-fact maintainer of the debian package for ~5 years.
Replies (1)
-
@noahm@chaos.social 2024-03-29 21:07
@AndresFreundTec@mastodon.social Indeed; I mis-read your oss-security post early on and thought that 5.6.1 was the one that introduced the actual backdoor, while only the framework for it had been introduced in earlier versions. It may have been the "Note that the files were not even used for any "tests" in 5.6.0." sentence that threw me off.