(In reply to Thorsten Kukuk from comment #4) > As written, this will not help, we still have other patches which requires > sshd to be linked against libsystemd it helps but is not sufficient. the login patch could be using plain dbus-1 for example. > and libsystemd will be loaded via > dlopen() anyways. Which opens the question: does the backdoor work, if > liblzma is loaded as dependency via dlopen()? I believe it doesn't because it depends on the IFUNCs being executed before libcrypto is initialized.