diff --git a/affected/vulnerabilities/index.html b/affected/vulnerabilities/index.html index 3213b3e8..e5830eeb 100644 --- a/affected/vulnerabilities/index.html +++ b/affected/vulnerabilities/index.html @@ -1,5 +1,5 @@ -
© Info :: LinuxServer.io, 2024
diff --git a/affected/vulnerabilities/index.json b/affected/vulnerabilities/index.json
index d3f0f628..85e4d94a 100644
--- a/affected/vulnerabilities/index.json
+++ b/affected/vulnerabilities/index.json
@@ -1 +1 @@
-{"is":"system","title":"Vulnerabilities","permalink":"https://info.linuxserver.io/affected/vulnerabilities/","status":"notice","pages":[{"is":"issue","title":"Regarding CVE-2024-3094 - Supply Chain Compromise Affecting XZ Utils","createdAt":"2024-03-29 22:00:00 +0000 UTC","lastMod":"2024-03-29 20:30:57 +0000 UTC","permalink":"https://info.linuxserver.io/issues/2024-03-29-cve-2024-3094/","severity":"notice","resolved":false,"informational":false,"resolvedAt":" Regarding CVE-2024-3094 - Supply Chain Compromise Affecting XZ Utils → A supply chain compromise has been discovered in the XZ Utils data compression library, being tracked under CVE-2024-3094, which could allow remote code execution under certain circumstances. The original report is available here if you are interested in the technical details. We have evaluated all of our current base images for indications that they may be vulnerable to this exploit: Regarding CVE-2024-3094 - Supply Chain Compromise Affecting XZ Utils → Further analysis of the exploit code indicates that it is only functional on amd64 hardware running glibc and a deb or rpm-based Linux distribution. The original CISA alert stated that the exploit could allow remote code execution, however, it remains unclear exactly what the payload was intended to do and so they have changed their description to “may allow unauthorized access to affected systems”. As best we can tell at this point, none of our images were or are… A supply chain compromise has been discovered in the XZ Utils data compression library, being tracked under CVE-2024-3094, which could allow remote code execution under certain circumstances. The original report is available here if you are interested in the technical details. We have evaluated all of our current base images for indications that they may be vulnerable to this exploit: So far the only exploitation path that has been observed is via SSH, and so in the vast majority of cases could not be exploited in any of our container environments, but we always recommend that you ensure any internet-facing containers are properly secured and kept up to date. We will update this post as and when more information becomes available. Last updated:
-March 29, 2024 at 8:30 PM © Info :: LinuxServer.io, 2024
+ Further analysis of the exploit code indicates that it is only functional on amd64 hardware running glibc and a deb or rpm-based Linux distribution. The original CISA alert stated that the exploit could allow remote code execution, however, it remains unclear exactly what the payload was intended to do and so they have changed their description to “may allow unauthorized access to affected systems”. As best we can tell at this point, none of our images were or are impacted by this vulnerability, but our original recommendations remain in place. A supply chain compromise has been discovered in the XZ Utils data compression library, being tracked under CVE-2024-3094, which could allow remote code execution under certain circumstances. The original report is available here if you are interested in the technical details. We have evaluated all of our current base images for indications that they may be vulnerable to this exploit: So far the only exploitation path that has been observed is via SSH, and so in the vast majority of cases could not be exploited in any of our container environments, but we always recommend that you ensure any internet-facing containers are properly secured and kept up to date. We will update this post as and when more information becomes available. Last updated:
+March 30, 2024 at 12:32 PM © Info :: LinuxServer.io, 2024
• Back to top LinuxServer.io Status page ⚡
Subscribe via RSS —
to all updatesUpdate - 2024-03-30
History
Regarding CVE-2024-3094 - Supply Chain Compromise Affecting XZ Utils
◆
-March 29, 2024 at 10:00 PM
+(8)March 29, 2024 at 10:00 PMRegarding CVE-2024-3094 - Supply Chain Compromise Affecting XZ Utils
◆
+This issue is not resolved yet
March 21, 2024 at 4:00 PMendlessh Deprecation Notice ℹ
Due to a lack of upstream development, we have decided to deprecate our endlessh container.
March 20, 2024 at 10:00 PMDillinger Deprecation Notice ℹ
Due to a lack of upstream development, we have decided to deprecate our dillinger container.
February 10, 2024 at 6:00 PMNew Container: Speedtest Tracker ℹ
We have released a new container for Speedtest Tracker!
diff --git a/index.json b/index.json
index e649d64a..54cae336 100644
--- a/index.json
+++ b/index.json
@@ -1 +1 @@
-{"is":"index","cStateVersion":"5.6.1","apiVersion":"2.0","title":"Info :: LinuxServer.io","languageCodeHTML":"en","languageCode":"en","baseURL":"https://info.linuxserver.io","description":"LinuxServer.io Status page","summaryStatus":"notice","categories":[{"name":"Images","description":"Information regarding our images","hideTitle":false,"closedByDefault":false},{"name":"Security","hideTitle":false,"closedByDefault":false}],"pinnedIssues":[],"systems":[{"name":"Deprecations","category":"Images","status":"ok","unresolvedIssues":[]},{"name":"New Containers","category":"Images","status":"ok","unresolvedIssues":[]},{"name":"Vulnerabilities","category":"Security","status":"notice","unresolvedIssues":[{"is":"issue","title":"Regarding CVE-2024-3094 - Supply Chain Compromise Affecting XZ Utils","createdAt":"2024-03-29 22:00:00 +0000 UTC","lastMod":"2024-03-29 20:30:57 +0000 UTC","permalink":"https://info.linuxserver.io/issues/2024-03-29-cve-2024-3094/","severity":"notice","resolved":false,"informational":false,"resolvedAt":"Regarding CVE-2024-3094 - Supply Chain Compromise Affecting XZ Utils
March 29, 2024 at 10:00 PM◆
-This issue is not resolved yetRegarding CVE-2024-3094 - Supply Chain Compromise Affecting XZ Utils
March 29, 2024 at 10:00 PM◆
+This issue is not resolved yetUpdate - 2024-03-30
Original Post
Regarding CVE-2024-3094 - Supply Chain Compromise Affecting XZ Utils
◆
-March 29, 2024 at 10:00 PM
+Regarding CVE-2024-3094 - Supply Chain Compromise Affecting XZ Utils
◆
+This issue is not resolved yet
March 21, 2024 at 4:00 PMendlessh Deprecation Notice ℹ
Due to a lack of upstream development, we have decided to deprecate our endlessh container.
March 20, 2024 at 10:00 PMDillinger Deprecation Notice ℹ
Due to a lack of upstream development, we have decided to deprecate our dillinger container.
February 10, 2024 at 6:00 PMNew Container: Speedtest Tracker ℹ
We have released a new container for Speedtest Tracker!
diff --git a/issues/index.json b/issues/index.json
index 1fb63a3e..efe582bc 100644
--- a/issues/index.json
+++ b/issues/index.json
@@ -1 +1 @@
-{"is":"issues","title":"Issues","baseURL":"https://info.linuxserver.io","description":"","pages":[{"is":"issue","title":"Regarding CVE-2024-3094 - Supply Chain Compromise Affecting XZ Utils","createdAt":"2024-03-29 22:00:00 +0000 UTC","lastMod":"2024-03-29 20:30:57 +0000 UTC","permalink":"https://info.linuxserver.io/issues/2024-03-29-cve-2024-3094/","severity":"notice","resolved":false,"informational":false,"resolvedAt":"