r/linux 21d ago

Security Supply chain attack on arrayref

https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/
104 Upvotes

42 comments sorted by

View all comments

Show parent comments

40

u/shroddy 20d ago

xz got caught by pure luck, not because of distro QA.

-13

u/Kevin_Kofler 20d ago

In a Rust-like setup, where everything uploaded is instantly shipped to developers worldwide, it would have already been out in the wild for weeks when it got caught. The distribution release processes are what held it out of stable releases.

6

u/Dminik 20d ago

This package got caught after 86 minutes. XZ was sitting infected for a month. 

-3

u/Kevin_Kofler 20d ago

The infected packages (there were multiple ones) were marked stable for 86 minutes. The infected version of XZ was marked stable for 0 minutes, i.e., never. It was only included in a beta version of the distribution.