I accidentally found a security issue while benchmarking postgres changes.

If you run debian testing, unstable or some other more "bleeding edge" distribution, I strongly recommend upgrading ASAP.

https://www.openwall.com/lists/oss-security/2024/03/29/4

oss-security - backdoor in upstream xz/liblzma leading to ssh server compromise

@AndresFreundTec This is incredible work, thank you so much.
@CyrilBrulebois @AndresFreundTec I concur — we are all your debt for spotting it so early.
@baloo @Aissen @CyrilBrulebois @AndresFreundTec 1000% agree. This was a really gnarly backdoor to track down and could have lived on for much longer with a much broader impact otherwise. It sucks that it got into Debian Testing and Fedora 40 Beta, but very very fortunate that it didn't get into GA stable releases as it very likely might have otherwise.