From 472fb74ece2d8a1f6df7fb4ffc6db8c7c43b81f7 Mon Sep 17 00:00:00 2001 From: Xe Iaso Date: Fri, 29 Mar 2024 13:44:05 -0400 Subject: CVE-2024-3094 Signed-off-by: Xe Iaso --- lume/src/notes/2024/xz-vuln.mdx | 2 ++ 1 file changed, 2 insertions(+) diff --git a/lume/src/notes/2024/xz-vuln.mdx b/lume/src/notes/2024/xz-vuln.mdx index 3887874..93fb52a 100644 --- a/lume/src/notes/2024/xz-vuln.mdx +++ b/lume/src/notes/2024/xz-vuln.mdx @@ -7,6 +7,8 @@ hero: prompt: "A stop sign on a blue sky with the words 'security alert' underneath it" --- +UPDATE(M03-29-2024 13:43-EDT): This is [CVE-2024-3094](https://nvd.nist.gov/vuln/detail/CVE-2024-3094). + This is a new situation and we are still gathering information. Here is what we know so far: The [xz/liblzma project](https://github.com/tukaani-project/xz) has released versions 5.6.0 and 5.6.1. -- cgit v1.2.3