Critical severity10.0NVD Advisory· Published Mar 29, 2024· Updated Jun 17, 2026
CVE-2024-3094
CVE-2024-3094
Description
Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
37- osv-coords35 versionspkg:apk/chainguard/opensshpkg:apk/chainguard/openssh-clientpkg:apk/chainguard/openssh-docpkg:apk/chainguard/openssh-keygenpkg:apk/chainguard/openssh-keyscanpkg:apk/chainguard/openssh-keysignpkg:apk/chainguard/openssh-pam-configpkg:apk/chainguard/openssh-pam-configurationpkg:apk/chainguard/openssh-pkcs11-helperpkg:apk/chainguard/openssh-serverpkg:apk/chainguard/openssh-server-configpkg:apk/chainguard/openssh-servicepkg:apk/chainguard/openssh-sftp-serverpkg:apk/chainguard/openssh-sk-helperpkg:apk/chainguard/xzpkg:apk/chainguard/xz-devpkg:apk/chainguard/xz-docpkg:apk/wolfi/opensshpkg:apk/wolfi/openssh-clientpkg:apk/wolfi/openssh-docpkg:apk/wolfi/openssh-keygenpkg:apk/wolfi/openssh-keyscanpkg:apk/wolfi/openssh-keysignpkg:apk/wolfi/openssh-pam-configpkg:apk/wolfi/openssh-pam-configurationpkg:apk/wolfi/openssh-pkcs11-helperpkg:apk/wolfi/openssh-serverpkg:apk/wolfi/openssh-server-configpkg:apk/wolfi/openssh-servicepkg:apk/wolfi/openssh-sftp-serverpkg:apk/wolfi/openssh-sk-helperpkg:apk/wolfi/xzpkg:apk/wolfi/xz-devpkg:apk/wolfi/xz-docpkg:rpm/opensuse/xz&distro=openSUSE%20Tumbleweed
< 0+ 34 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 5.6.2-1.1
Patches
Vulnerability mechanics
References
53- access.redhat.com/security/cve/CVE-2024-3094nvdVendor Advisory
- arstechnica.com/security/2024/03/backdoor-found-in-widely-used-linux-utility-breaks-encrypted-ssh-connections/nvdThird Party Advisory
- aws.amazon.com/security/security-bulletins/AWS-2024-002/nvdThird Party Advisory
- boehs.org/node/everything-i-know-about-the-xz-backdoornvdThird Party Advisory
- bugs.debian.org/cgi-bin/bugreport.cginvdMailing ListVendor Advisory
- bugs.gentoo.org/928134nvdIssue TrackingThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
- bugzilla.suse.com/show_bug.cginvdIssue TrackingThird Party Advisory
- discourse.nixos.org/t/cve-2024-3094-malicious-code-in-xz-5-6-0-and-5-6-1-tarballs/42405nvdThird Party Advisory
- gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27nvdThird Party Advisory
- github.com/advisories/GHSA-rxwq-x6h5-x525nvdThird Party Advisory
- gynvael.coldwind.plnvdTechnical DescriptionThird Party Advisory
- lists.debian.org/debian-security-announce/2024/msg00057.htmlnvdMailing ListThird Party Advisory
- lists.freebsd.org/archives/freebsd-security/2024-March/000248.htmlnvdThird Party Advisory
- lwn.net/Articles/967180/nvdIssue TrackingThird Party Advisory
- news.ycombinator.com/itemnvdIssue TrackingThird Party Advisory
- openssf.org/blog/2024/03/30/xz-backdoor-cve-2024-3094/nvdThird Party Advisory
- security-tracker.debian.org/tracker/CVE-2024-3094nvdThird Party Advisory
- security.alpinelinux.org/vuln/CVE-2024-3094nvdThird Party Advisory
- security.archlinux.org/CVE-2024-3094nvdThird Party Advisory
- tukaani.org/xz-backdoor/nvdIssue TrackingVendor Advisory
- twitter.com/LetsDefendIO/status/1774804387417751958nvdThird Party Advisory
- ubuntu.com/security/CVE-2024-3094nvdThird Party Advisory
- www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094nvdThird Party AdvisoryUS Government Resource
- www.darkreading.com/vulnerabilities-threats/are-you-affected-by-the-backdoor-in-xz-utilsnvdThird Party Advisory
- www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-usersnvdVendor Advisory
- www.tenable.com/blog/frequently-asked-questions-cve-2024-3094-supply-chain-backdoor-in-xz-utilsnvdThird Party Advisory
- xeiaso.net/notes/2024/xz-vuln/nvdThird Party Advisory
- news.ycombinator.com/itemnvdIssue Tracking
- twitter.com/debian/status/1774219194638409898nvdPress/Media Coverage
- twitter.com/infosecb/status/1774595540233167206nvdPress/Media Coverage
- twitter.com/infosecb/status/1774597228864139400nvdPress/Media Coverage
- www.openwall.com/lists/oss-security/2024/03/29/4nvdMailing List
- www.theregister.com/2024/03/29/malicious_backdoor_xz/nvdPress/Media Coverage
- www.openwall.com/lists/oss-security/2024/03/29/10nvd
- www.openwall.com/lists/oss-security/2024/03/29/12nvd
- www.openwall.com/lists/oss-security/2024/03/29/4nvd
- www.openwall.com/lists/oss-security/2024/03/29/5nvd
- www.openwall.com/lists/oss-security/2024/03/29/8nvd
- www.openwall.com/lists/oss-security/2024/03/30/12nvd
- www.openwall.com/lists/oss-security/2024/03/30/27nvd
- www.openwall.com/lists/oss-security/2024/03/30/36nvd
- www.openwall.com/lists/oss-security/2024/03/30/5nvd
- www.openwall.com/lists/oss-security/2024/04/16/5nvd
- ariadne.space/2024/04/02/the-xz-utils-backdoor-is-a-symptom-of-a-larger-problem/nvd
- blog.netbsd.org/tnf/entry/statement_on_backdoor_in_xznvd
- news.ycombinator.com/itemnvd
- research.swtch.com/xz-scriptnvd
- research.swtch.com/xz-timelinenvd
- security.netapp.com/advisory/ntap-20240402-0001/nvd
- www.binarly.io/blog/persistent-risk-xz-utils-backdoor-still-lurking-in-docker-imagesnvd
- www.kali.org/blog/about-the-xz-backdoor/nvd
- www.vicarius.io/vsociety/vulnerabilities/cve-2024-3094nvd
News mentions
0No linked articles in our index yet.