Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

fwiw, fix available in openbsd patch https://ftp.openbsd.org/pub/OpenBSD/patches/7.2/common/017_s... (run "doas syspatch" if you haven't in a while)

spot checking, debian stable, ubuntu 22.04 lts and rhel 7/8/9 all ship pre-9.1 openssh which aren't affected, if that helps put anyone else's mind at ease a bit.



This is already mentioned in a different comment here[1], but for ease of reference, Arch Linux did ship a vulnerable version and released the fix on 2 February[2].

[1] https://news.ycombinator.com/item?id=34713862

[2] https://github.com/archlinux/svntogit-packages/commit/796878...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: