fa
Feedback
Debian 踩坑预警

Debian 踩坑预警

رفتن به کانال در Telegram
327
مشترکین
اطلاعاتی وجود ندارد24 ساعت
+37 روز
+830 روز
آرشیو پست ها
Debian Bug report logs - #1076729 libwayland: breaks plasma desktop start after last upgrade to version 1.23.0-1

今天滚动的人小心 glibc 跳大版本,2.38 -> 2.39

慢报:gnome-shell 46 已登陆 Debian sid。可正常安装。

Debian Bug report logs - #996202 systemd - EFI Secure Boot for systemd-boot systemd-boot 尚不支持 secure boot,但是有希望

Mutter/GNOME Shell transition 将在 time_t transition 结束后开始。 好消息:可以等到 GNOME 新版本 坏消息:在重新可构建和安装之前,budgie-desktop 将从 testing 中移除

Debian Bug report logs - #1067117 budgie-desktop: Fails to build with mutter >= 45

已知影响为在sshd中创造pubkey登录后门(更新:RCE)

⚠xz-utils 恶意代码警告⚠ xz 5.5.1至5.6.1含有恶意代码,debian testing/sid 用户请立即更新至 5.6.1+really5.4.5-1。 近两个月更新过系统的用户,请立即检查xz版本,示例代码: xz -V xz (XZ Utils) 5.2.4 liblzma 5.2.4 本次投毒手法极为复杂,刻意规避代码审计,仅针对deb/rpm系打包,目的在于创造sshd pubkey登录后门。如果您向公网暴露含有后门的ssh服务,且暂无法更新系统,请立即封堵相关端口,并检查所有可疑登录迹象。 相关链接: https://www.openwall.com/lists/oss-security/2024/03/29/4 https://t.me/CE_Observe/32247

xz 包上游被投毒后门,Debian testing 和 sid 用户受影响,影响 5.5.1alpha-0.1 至 5.6.1-1 版本,建议尽快升级

Compromised packages were part of the Debian testing, unstable and experimental distributions, with versions ranging from 5.5.1alpha-0.1 (uploaded on 2024-02-01), up to and including 5.6.1-1. The package has been reverted to use the upstream 5.4.5 code, which we have versioned 5.6.1+really5.4.5-1. Users running Debian testing and unstable are urged to update the xz-utils packages.

[SECURITY] [DSA 5649-1] xz-utils security update

First packages of KF6 accepted into experimental

关于 unstable 当前 grub 状态:Debian Bug report logs - #1067486 Depends: grub-common (= 2.12-1) but it is not going to be installed

unstable 实测 GNOME/KDE 环境目前均可 full-upgrade 到最新状态,忍不住的可以考虑升级了(⚠️再次提醒,不同机器软件包量不同,升级前请仔细核对移除的软件清单是否都在预期之内,谨防翻车)

另外这次严禁软件包降级,会直接丢文件 已经有受害者在邮件列表上出现了 (真要降级的话请降完之后,再一次手动把所有降级的软件包重装一遍)

sid 用户先锁死当前状态别动弹,这次动作比较大

最近一堆 time_t 64 的 transition 在跑,其他的升级也可以缓缓(