this post was submitted on 19 Mar 2025
89 points (92.4% liked)

Linux

56758 readers
665 users here now

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

Related Communities

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

founded 6 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] LordPassionFruit@lemm.ee 27 points 4 months ago (2 children)

I've tried reading through the article, but unfortunately, I'm not the sharpest tool in the shed. I use openSUSE, how does this affect me, and what do I need to do/what can I do about this?

[–] that_leaflet@lemmy.world 50 points 4 months ago* (last edited 4 months ago) (2 children)

You don’t need to do anything, these issues have already been fixed.

[–] LordPassionFruit@lemm.ee 17 points 4 months ago

Perfect. Thank you for taking the time to respond

[–] blackbrook@mander.xyz 3 points 4 months ago* (last edited 4 months ago) (1 children)

Do you mean the specific exploit performed by the author has been fixed? Or the general vulnerability that this exploit was intended to demonstrate has been fixed? The article ends with a What's Next section discussing the difficulty of the latter, saying

we don’t think there’s a silver bullet to address the risks caused by the compromise of such central pieces of infrastructure

and going into detail about the challenges for openSUSE OBS. Are you claiming those challenges have all been solved and exploits like this are no longer possible?

[–] that_leaflet@lemmy.world 6 points 4 months ago

The authors found and reported vulnerabilities in Pagure and Open Build Service. These vulnerabilities have since been fixed.

[–] JustAnotherKay@lemmy.world 14 points 4 months ago

Usually with vulnerabilities like this, they're not gonna say anything about it until after they patch it so that people don't go abuse it