Regarding CVE-2024-3094 - Supply Chain Compromise Affecting XZ Utils →
Further analysis of the exploit code indicates that it is only functional on amd64 hardware running glibc and a deb or rpm-based Linux distribution. The original CISA alert stated that the exploit could allow remote code execution, however, it remains unclear exactly what the payload was intended to do and so they have changed their description to “may allow unauthorized access to affected systems”.
As best we can tell at this point, none of our images were or are…