After 2024-04-02 I am only adding important new discoveries (I come accross). There is just too much Blog and Video entries to keep track of.
Initial disclosure:
- https://www.openwall.com/lists/oss-security/2024/03/29/4
- Aka https://lwn.net/ml/oss-security/[email protected]/
CVE and Alerts
- https://github.com/advisories/GHSA-rxwq-x6h5-x525
- https://nvd.nist.gov/vuln/detail/CVE-2024-3094
- https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094