protonscr

Steam Dependency on xz-utils (CVE-2024-3094)

steamclosed
ValveSoftware/steam-for-linux#10709 · opened 2024-03-30 by AffSeda · updated 2024-03-30 · 2 comments · github
AAffSeda 2024-03-30 github

Your system information

  • Steam client version (build number or date): 1709846872
  • Distribution (e.g. Ubuntu): Debian
  • Opted into Steam client beta?: No
  • Have you checked for system updates?: Yes
  • Steam Logs: Not Applicable
  • GPU: AMD

Please describe your issue in as much detail as possible:

It's possible the current xz-utils package is, was, and always will be potentially malicious. Is it possible that the Steam client can be reworked to not require this package?

Kkaarelen 2024-03-30 github

@AffSeda It doesn't work like that. Something like that could happen with any library - it's not the reason for starting a witch hunt. Backdoor is detected and patched. End of the story.

But you are right - it HAS to be checked.

Kkisak-valve maintainer 2024-03-30 github

Hello @AffSeda, in general, Steam uses the host system libraries or libraries from Steam Linux Runtime.

You can review the libraries used in the various Steam Linux Runtime container environments at https://repo.steampowered.com/.

In particular, Steam Linux Runtime - Scout (https://repo.steampowered.com/steamrt-images-scout/snapshots/latest-steam-client-general-availability/sources/) has xz-utils_5.1.1alpha+20110809-3 and Steam Linux Runtime - Sniper (https://repo.steampowered.com/steamrt-images-sniper/snapshots/latest-container-runtime-depot/sources/) has xz-utils_5.2.5-2.1~deb11u1.

This summary predates the CVE in question.

Nothing extracted yet.