Xz library CVE is TurrisOS vulnerable?

https://www.openwall.com/lists/oss-security/2024/03/29/4

1 Like

Seems like HBS has too old xz library and thus not vulnerable. Funny

2 Likes

My understanding is that the mechanism relies on glibc and thus won’t work on musl.

2 Likes

History/timeline

The up to date TurrisOS 6.5.2 HBS has xz --version = 5.2.5 and the CVE NVD - CVE-2024-3094 states version 5.6.0+ is vulnerable, hence it’s likely your Turris is not vulnerable.

1 Like

This topic was automatically closed 3 days after the last reply. New replies are no longer allowed.