The xz package that has already entered the current F40 pre-release versions/variants and rawhide contains malicious code.  This does NOT affect users of the Fedora releases (F38, F39 are thus not affected), but all users who use already F40 pre-release versions/variants or rawhide shall read this:  Article:   CVE details:  https://access.redhat.com/security/cve/CVE-2024-3094  Be aware that this is CVE criticality 10: this is the highest risk factor.  Also be aware that the header of the RH arti...
On Ubuntu the only affected people were those running the prerelease of Ubuntu 24.04 who had installed the update from the
proposedpocket.