openSUSE Tumbleweed users where SSH is exposed to the internet it's recommended to do a fresh install due the recently discovered supply chain attack against xz compression library, as it’s unknown if the backdoor has been exploited.

https://news.opensuse.org/2024/03/29/xz-backdoor/

#opensuse #tumbleweed #linux #supplychainattack #xz #compressionlibrary #supply_chain_attack #compression_library #opensuse_tumbleweed #suse #sles

openSUSE addresses supply chain attack against xz compression library

openSUSE maintainers received notification of a supply chain attack against the “xz” compression tool and “liblzma5” library. Background Andres Freund report...

openSUSE News