Red Hat released an urgent security alert for Fedora 41 and Rawhide users:
> PLEASE IMMEDIATELY STOP USAGE OF ANY FEDORA 41 OR FEDORA RAWHIDE INSTANCES for work or personal activity.
https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users
> Although Fedora 40 beta contained the 5.6 version of xz in an update, the build environment prevents the injection from correctly occurring, and has not been shown to be compromised. Fedora 40 has now reverted to the 5.4.x versions of xz.
Red Hatter rwmj on https://news.ycombinator.com/item?id=39866275:
> the apparent author of the backdoor was in communication with me over several weeks trying to get xz 5.6.x added to Fedora 40 & 41 because of it's "great new features". We even worked with him to fix the valgrind issue (which it turns out now was caused by the backdoor […]
> He has been part of the xz project for 2 years, adding all sorts of binary test files
> with this level of sophistication I would be suspicious of even older versions of xz
Red Hatter rwmj on https://news.ycombinator.com/item?id=39866275:
> the apparent author of the backdoor was in communication with me over several weeks trying to get xz 5.6.x added to Fedora 40 & 41 because of it's "great new features". We even worked with him to fix the valgrind issue (which it turns out now was caused by the backdoor […]