• germanatlas@lemmy.blahaj.zone
    link
    fedilink
    arrow-up
    4
    ·
    3 months ago

    no real-world use found for staying more than one version behind

    The ssh vulnerability didn’t affect Debian because the packages were too many versions behind

    • azvasKvklenko@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      1
      ·
      3 months ago

      AFAIK, the xz vulnerability was designed for Debian based on its workaround fixing systemd service status detection. Even if it shipped to something like Arch, the malicious code wouldn’t load.