XZ story REVISED: Should we apologize or demand an apology – This crisis is placing all of us under the test CVE-2024-3094

Systems running without systemd are apparently safe

What crisis?  CVE-2024-3094
Compromised lzma library triggered by an openssh-hook to systemd notify (sd_notify) to obtain code hidden in liblzma to create a backdoor to any debian/fedora/ubuntu ssh server.  Apparently not even openssh-selinux is safe under those conditions (glibc, x86-64, preconfigured tarball source from github 5.6.0 and 5.6.1, systemd, openssh, rpm or deb packaging, with enabled calls to systemd through the openssh.service ).  If source was built from git with native clean autoconf/make the suspect code is not included.  Musl systems have nothing to worry about, probably because they can’t compile sd_notify to trigger this whole thing.

Psychopath, paranoid, not knowing shit about software

When we criticized zstd and advocated that long term friend xz, suspecting zstd of a trojan horse for security and encryption, those were some of the names I/we were called by the fan-club of facebook-hired ex-military author of zstd.  Mind you zstd is commonly built with lzma library enabled!

IMPOSSIBLE, it is just a compression algorithm, it can’t be used to exploit security of a system. they said

Sorry, I may had no clue how but IT IS now POSSIBLE!!!

Good news:  As far as experts in debian fedora arch ubuntu can TELL it takes systemd  to energize the backdoor, specifically a hook used by debian to build openssh a certain way that systemd/dbus/sd-bus/sd-notify run rogue code to obtain material from a blob (check/test result) from lzma to modify running binaries to open the backdoor.

Ok, no victory claimed here with the misery of others, not apologizing for xz, every distribution in the universe used it, and NOBODY KNOWS if the same or similar has happened in other FOSS or other compression algorithms, this is fresh off the press.  It will take some time for dust to clear up!

Scenarios: Ok ok, this scenario was too far unrealistic (ssh to m/v Dali and shutting it down) , I take it down, here is another:

Scenario #2: The aim was not to hack a system, AFAIK there have been no systems violated because the few running a debian/ubuntu/fedora/RHell testing/unstable ssh server would be hard to discover and hack.  The aim was not to provide anyone discovering it a backdoor to any system, too early to become stable as 5.6.0/5.6.1 so what was the aim?

The aim was to discredit and essential traditional utility found on any distro NOT COMING from a major corporation or other corporation affiliated entity (like IBM, facebook, google) and in the minds of the many to steer them to a more “reliable” corporate “product”.  Should I name it?

The fact that the technical goal was achieved/achieveable was the victory for whoever can document they were Jia Cheong Tan, that will get them some lucrative security pen/test position.

The funny part I cut/copy/pasted this, it is not mine, it is public domain but thumbs up for the genius that thought this way! 🙂

An analysis of that nick name revearls this:

JIA CHEONG TAN
CIA JHEONG TAN
CIA JHON EGTAN
CIA JOHN AGENT
CIA AGENT JOHN
Case closed

 

Bibliography of this mini-tragedy for systemd and the “provocative” vindication of zstd (which usually is compiled using lib-lzma).

Here is some reading material to print and keep on your bedside:

 

6 thoughts on “XZ story REVISED: Should we apologize or demand an apology – This crisis is placing all of us under the test CVE-2024-3094

  1. What do you call an intelligence agency who shamelessly tried to exploit millions of people’s freedom and security? It rhymes with “Jia A”!

    Like

    • North Korea, Iran, Syria, Iraq, Yemen, Venezuela, Cuba, Nicaragua, Armenia, Novorussia – Security and Intelligence Agency?

      I am running out of guesses here, help me out 🙂

      Edit: I thought after Snowden’s public appeal that massive riots in the entire western world would bring down the dictatorship of uncle Sam’s patriarchal banking and military industry welfare system. But we live and learn, how deep and toxic indoctrination and conditioning can be in the western world, or maybe how deeply class conscious western workers have become over the exploitation mechanism of the remaining world maintains their living conditions. Just like in old feuds and kingdoms which were localized, you use an army to oppress and exploit the masses around the feud, and sprinkle some extra crumbs for the soldiers who protect you and collect for you.
      A globalized feudal system maintaining western European and N.American oligarchy.

      Let’s hope on how greed can overcome the greedy, peasants and soldiers will converge in deteriorating living conditions, and they will have nothing to use their intelligence database to protect them.

      We are also too immature to comprehend the zapatistas experiment, they have been struggling for autonomy 500+ years, we have been doing it for 150, and have become idle in the past 50 re-enacting 1880s and 1960s pointless ceremonies.

      Like

      • I want to thank you for keeping up this website. It is my grounding. Recently I have pointed my son this way as he comes into his own learning the issues surrounding systemd. He is up and coming now into this, and I appreciate being able to have somewhere to send him to learn on his own.

        Ah it just keeps going doesnt it. Like for real, will it take the kernal blowing up a mainframe, because it over cooked from the 9 zillion unnessesary movements from systemd to come full stop. The distros are just flatlining in performance. I. just. cant . believe these devs just keep going along to get along. what. what is going on in their heads right. For real.

        Remember when linux worked? like it went on in less than 10 minutes. Booted to desktop in 7 seconds. Had all the goodies ready to go Remember that? wasn’t that long ago . Dude.

        I check in here about 1x month. As my desktop continues to implode week after week. install after install. Yeah, dudes on these forums out there all ready with “you dont know how to use linux, you are a newbi, you are just inexperienced..” and on and on, scroll-blame-scroll-blame its all wonderful and good as per the replies. Gotta wonder-Bots? Really, you gonna defend this ball of flames of an os.

        I gotta lot of respect for the devs fighting it. The biggest issue is this. Like Smr hard drives, it is just a huge circle jerk. They put one systemd fire out and pottering sends out another one. boom square one.

        ASCII had less than 5 systemd shims. Chimera has 77. Havent counted Daedalus yet. Could barely get the sucker on my machine then-crash and burn.

        Systemd s Fkng everywhere. Man. Its cancer.

        Theres EULas in KDE, well what amounts to a EULA anyway, yeah-what.is happening. KDE Coo l Guys. We called them posers back in the day.

        Slack 14.2 and 15, barely usable compared to 14.1.

        Basic system support is nearly non existant at this point, I am at pkgs.org to find the repos then dig back to find simple shit like python, amducode, intel microcode, should be in the non free repos where is it.- is there a working version of xfcewm?

        Client side decoration-is this windows on linux? Really gotta say. Because it mirrors windows 10 DE bullshit. same coin different sides. Dude, grub.dont work. sorry does .not .work. hasnt Really worked. since 1.99. Lilo, yeah lets get rid of the only bootloader option that actually just works right? good job devs.

        Drop MBR support? Yeah? Because half the planet has MBR dude. Good job. UEFI only right? Systemd UEFI boot club. Yep think thats fitting.

        Its like. Being in the desert. 10 miles from the road. You gotta walk to the pavement, while at the same time, dragging a broken leg behind you. Gotta keep pulling it while also dragging it, at the same time,be careful it might lag– not too much weight can be applied while in transit.

        This blog, is my my grounding tool. I read it so I dont lose sight of the object. In the last two years. I have spent more time fixing linux than I have spent even doing one build on windows. xp.

        Its a dumpster fire.

        And.I dont think the way through is by circle jerking the systemd fires.

        I dont know what the answer is. I am not a coder. But this is a Tom and Jerry rerun. it will never end until the distros that are fighting this, just stop fighting it, and let go of the wheel.

        The only way out is to disconnect and redirect. The devs in the fight are probably so fucking tired of the systemd fires they keep having to put out. It explains the shims and their increases. Just buy a little more time.

        I stand by what I said few years back, linux will be windows, and vice versa in a very short time.

        The only way out, is collabaoration by ALL the distros currently in the fight. It will take everyone. Everyone. Gotta make a new operating system. Gotta get out of Linux/Mac/Windows. Gotta let go of the circle jerk.

        Systemd’s purpose (my opin)is to disect/divide/destroy and wear down the dissenters all.of linux. I think its been the function from the outset.

        If not , that is the effect it has had here 10 years later.

        Its almost over. I dont think FreeBSd will survive it either. I used to. But, the forums indicate it is bleeding in over there as well.

        My full respect for the Devuan Team, I think they are smashing their heads against the wall, and have been for along long time. Thanks for a good 4 years of stability. Current release will no longer install. —uefi.

        PCLOS-no more mbr, Freebsd install boots no more, GhostBSD buckels on install, sorry no more mbr support, the list is long, out of our 9 computers, 3 recent hardware builds, none can take a new linux install. Zen, installed updates til it removed the entire desktop and left me a shell. No. I will not turn on the ability for systemd shims/firmware to dig around in my hardware. I did not buy my hardware for pottering deciples.

        Its funny, all these distros claiming “good for old computers”…lalala-yeah dude–if you cant install it to the old computer – then its not -good- for the old computer. This also applies if you refuse to turn on UEFI.

        Alas, as it continues down the road of hardware annilation, systemd is taking out all the computers that it cant manipulate from the backend. Hence UEFI mandate. No BIOS. Yep, well, as I type this on a cobbled together slackware install, as I cant update or it blows up my desktop, that took 6 installs to get a desktop running—deleting innode—it shoehorned elilo during install to a computer that has no UEFI, then buckled on reboot-Fixing—-no uefi partition present–fixing–and I wont have a login manager, because I just cant deal with anymore broken shit right now. At least the audio works.

        My plan is to find a defunct distro no one looks at and tweak it for myself. The less running on dbus the better.

        The community has got to sit down, and make a plan, or its just all going to burn down, then all we will be left will is old distros to build with using virtual box to boot anything new.

        We need New Code.

        C. Python. PHP. Raw. New Kernal. New Browser. No Forks. Basic language that intersects with everything else. Backwards Compatibility to 2000 hardware. Forward Hardware Compatibility to whenever. No more Desktop enviornment forks. no more shims. no more trying to include all the software everyone knows.

        Back to reality.

        And no one will get this done on their own. It will take every single distro that hasn’t caved and/or is running on shims to input. Thats what it will take. And it will take 10 years. If the devs that split 10 years ago did this ten years ago, we would be up and running now.

        The distros and Devs Gotta drop the drama and get real.

        Its coming. The Windows Linux Marriage is coming.

        Just a housewife, and thats my take. I Want to say thanks alot for this site and all the effort you put into these articles.

        I’m Out.

        Sally

        Like

        • One of the happiest notes I read Sally, especially about “son learning”.
          The problem as I see it is not in the terms of publicity and marketing the alternatives but in the small amount of people thinking, and by thinking I mean critically. They will find their way no matter how much mass media works against us. It is just a rational choice, it is not being a fan-club of some mindless sport.

          The simpler the system, the easiest and safer to control, the easier to trouble shoot and repair.
          I am proud to say this system I write on is the evolution of the very same installation from 7y back.

          Like

  2. In another comment on 20240330 sysdfree-editor says:   

    > Hi Yann, I hope you’ve been alerted about the xz issue, if you have built xz 5.6.0/5.6.1 from tarball with gcc you may want to take a look at the latest article.

    Generally speaking, I always wait a little before using a new version.

    So I download an even-numbered month and I distribute the version the next month in order to be almost certain to have software that are pretty much stable.

    In the case of superBoxon 23-11, I downloaded the snapshot on October 23 and the final version was released on November 23.

    For the next version that will be released exceptionally in April, I will use a February snapshot.

    So version 23.11 used version 5.4.4 of xz and for 24.03 I will use 5.4.6, both coming straight from the stock Slackware, no need to recompile them.

    About the xz case:

    It seems that an archive has been specially forged to replace the original automatically-generated source code archive, so nobody could have noticed the manipulation without making a new archive with the same version of the original source code to compare the two.

    Besides being virtually undetectable, it’s pretty smart, but it will force us to do this check if we have any doubts about the source archive we’re using.

    It wasn’t hard enough…

    Like

  3. …”JIA CHEONG TAN
    CIA JHEONG TAN
    CIA JHON EGTAN
    CIA JOHN AGENT
    CIA AGENT JOHN” …

    wow! what an insight! Briallliant!

    Like

If your comment is considered off-topic a new topic will be created with your comment to continue a different discussion. This community is based on open and free communication, meaning we must all respect all in minimizing the exercise of freedom to disrupt such communication. Feel free to post what you think but keep in mind the subject matter discussed. It is just as easy to start a new topic as it is to dilute the content of an existing discussion.

This site uses Akismet to reduce spam. Learn how your comment data is processed.