CVE-2024-3094
Detail
Modified After Enrichment
This CVE record has been updated after NVD enrichment efforts were completed. Enrichment data supplied by the NVD may require amendment due to these changes.
Description
Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0.
Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 4.0 Severity and Vector Strings:
NVD assessment
not yet provided.
CVSS 3.x Severity and Vector Strings:
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS 2.0 Severity and Vector Strings:
Base
Score:
NVD assessment
not yet provided.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [email protected].
Weakness Enumeration
| CWE-ID |
CWE Name |
Source |
|
CWE-506
|
Embedded Malicious Code |
Red Hat, Inc.
|
Change History
22 change records found show changes
CVE Modified by CISA-ADP
6/17/2026 3:43:17 AM
| Action |
Type |
Old Value |
New Value |
| Added |
SSVC |
{"timestamp":"2024-04-02T04:00:23.138684Z","id":"CVE-2024-3094","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}
|
CVE Modified by Red Hat, Inc.
6/17/2026 3:43:17 AM
| Action |
Type |
Old Value |
New Value |
| Added |
Affected |
[{"defaultStatus":"unaffected","collectionURL":"https://github.com/tukaani-project/xz","packageName":"xz","versions":[{"version":"5.6.0","status":"affected"},{"version":"5.6.1","status":"affected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"xz","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 6","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"xz","cpes":["cpe:/o:redhat:enterprise_linux:6"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"xz","cpes":["cpe:/o:redhat:enterprise_linux:7"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"xz","cpes":["cpe:/o:redhat:enterprise_linux:8"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"xz","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/jbossnetwork/restricted/listSoftware.html","packageName":"xz","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8"]}]
|
CVE Modified by CVE
8/18/2025 9:15:57 PM
| Action |
Type |
Old Value |
New Value |
| Added |
Reference |
https://www.binarly.io/blog/persistent-risk-xz-utils-backdoor-still-lurking-in-docker-images
|
CVE Modified by Red Hat, Inc.
2/06/2025 4:15:10 AM
| Action |
Type |
Old Value |
New Value |
| Removed |
Reference |
http://www.openwall.com/lists/oss-security/2024/03/29/10
|
| Removed |
Reference |
http://www.openwall.com/lists/oss-security/2024/03/29/12
|
| Removed |
Reference |
http://www.openwall.com/lists/oss-security/2024/03/29/4
|
| Removed |
Reference |
http://www.openwall.com/lists/oss-security/2024/03/29/5
|
| Removed |
Reference |
http://www.openwall.com/lists/oss-security/2024/03/29/8
|
| Removed |
Reference |
http://www.openwall.com/lists/oss-security/2024/03/30/12
|
| Removed |
Reference |
http://www.openwall.com/lists/oss-security/2024/03/30/27
|
| Removed |
Reference |
http://www.openwall.com/lists/oss-security/2024/03/30/36
|
| Removed |
Reference |
http://www.openwall.com/lists/oss-security/2024/03/30/5
|
| Removed |
Reference |
http://www.openwall.com/lists/oss-security/2024/04/16/5
|
| Removed |
Reference |
https://ariadne.space/2024/04/02/the-xz-utils-backdoor-is-a-symptom-of-a-larger-problem/
|
| Removed |
Reference |
https://arstechnica.com/security/2024/03/backdoor-found-in-widely-used-linux-utility-breaks-encrypted-ssh-connections/
|
| Removed |
Reference |
https://aws.amazon.com/security/security-bulletins/AWS-2024-002/
|
| Removed |
Reference |
https://blog.netbsd.org/tnf/entry/statement_on_backdoor_in_xz
|
| Removed |
Reference |
https://boehs.org/node/everything-i-know-about-the-xz-backdoor
|
| Removed |
Reference |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024
|
| Removed |
Reference |
https://bugs.gentoo.org/928134
|
| Removed |
Reference |
https://bugzilla.suse.com/show_bug.cgi?id=1222124
|
| Removed |
Reference |
https://discourse.nixos.org/t/cve-2024-3094-malicious-code-in-xz-5-6-0-and-5-6-1-tarballs/42405
|
| Removed |
Reference |
https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27
|
| Removed |
Reference |
https://github.com/advisories/GHSA-rxwq-x6h5-x525
|
| Removed |
Reference |
https://github.com/amlweems/xzbot
|
| Removed |
Reference |
https://github.com/karcherm/xz-malware
|
| Removed |
Reference |
https://gynvael.coldwind.pl/?lang=en&id=782
|
| Removed |
Reference |
https://lists.debian.org/debian-security-announce/2024/msg00057.html
|
| Removed |
Reference |
https://lists.freebsd.org/archives/freebsd-security/2024-March/000248.html
|
| Removed |
Reference |
https://lwn.net/Articles/967180/
|
| Removed |
Reference |
https://news.ycombinator.com/item?id=39865810
|
| Removed |
Reference |
https://news.ycombinator.com/item?id=39877267
|
| Removed |
Reference |
https://news.ycombinator.com/item?id=39895344
|
| Removed |
Reference |
https://openssf.org/blog/2024/03/30/xz-backdoor-cve-2024-3094/
|
| Removed |
Reference |
https://research.swtch.com/xz-script
|
| Removed |
Reference |
https://research.swtch.com/xz-timeline
|
| Removed |
Reference |
https://security-tracker.debian.org/tracker/CVE-2024-3094
|
| Removed |
Reference |
https://security.alpinelinux.org/vuln/CVE-2024-3094
|
| Removed |
Reference |
https://security.archlinux.org/CVE-2024-3094
|
| Removed |
Reference |
https://security.netapp.com/advisory/ntap-20240402-0001/
|
| Removed |
Reference |
https://tukaani.org/xz-backdoor/
|
| Removed |
Reference |
https://twitter.com/LetsDefendIO/status/1774804387417751958
|
| Removed |
Reference |
https://twitter.com/debian/status/1774219194638409898
|
| Removed |
Reference |
https://twitter.com/infosecb/status/1774595540233167206
|
| Removed |
Reference |
https://twitter.com/infosecb/status/1774597228864139400
|
| Removed |
Reference |
https://ubuntu.com/security/CVE-2024-3094
|
| Removed |
Reference |
https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094
|
| Removed |
Reference |
https://www.darkreading.com/vulnerabilities-threats/are-you-affected-by-the-backdoor-in-xz-utils
|
| Removed |
Reference |
https://www.kali.org/blog/about-the-xz-backdoor/
|
| Removed |
Reference |
https://www.tenable.com/blog/frequently-asked-questions-cve-2024-3094-supply-chain-backdoor-in-xz-utils
|
| Removed |
Reference |
https://www.theregister.com/2024/03/29/malicious_backdoor_xz/
|
| Removed |
Reference |
https://www.vicarius.io/vsociety/vulnerabilities/cve-2024-3094
|
| Removed |
Reference |
https://xeiaso.net/notes/2024/xz-vuln/
|
| Removed |
Reference Type |
https://arstechnica.com/security/2024/03/backdoor-found-in-widely-used-linux-utility-breaks-encrypted-ssh-connections/ Types: Third Party Advisory
|
| Removed |
Reference Type |
https://aws.amazon.com/security/security-bulletins/AWS-2024-002/ Types: Third Party Advisory
|
| Removed |
Reference Type |
https://boehs.org/node/everything-i-know-about-the-xz-backdoor Types: Third Party Advisory
|
| Removed |
Reference Type |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024 Types: Mailing List, Vendor Advisory
|
| Removed |
Reference Type |
https://bugs.gentoo.org/928134 Types: Issue Tracking, Third Party Advisory
|
| Removed |
Reference Type |
https://bugzilla.suse.com/show_bug.cgi?id=1222124 Types: Issue Tracking, Third Party Advisory
|
| Removed |
Reference Type |
https://discourse.nixos.org/t/cve-2024-3094-malicious-code-in-xz-5-6-0-and-5-6-1-tarballs/42405 Types: Third Party Advisory
|
| Removed |
Reference Type |
https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27 Types: Third Party Advisory
|
| Removed |
Reference Type |
https://github.com/advisories/GHSA-rxwq-x6h5-x525 Types: Third Party Advisory
|
| Removed |
Reference Type |
https://github.com/karcherm/xz-malware Types: Third Party Advisory
|
| Removed |
Reference Type |
https://gynvael.coldwind.pl/?lang=en&id=782 Types: Technical Description, Third Party Advisory
|
| Removed |
Reference Type |
https://lists.debian.org/debian-security-announce/2024/msg00057.html Types: Mailing List, Third Party Advisory
|
| Removed |
Reference Type |
https://lists.freebsd.org/archives/freebsd-security/2024-March/000248.html Types: Third Party Advisory
|
| Removed |
Reference Type |
https://lwn.net/Articles/967180/ Types: Issue Tracking, Third Party Advisory
|
| Removed |
Reference Type |
https://news.ycombinator.com/item?id=39865810 Types: Issue Tracking, Third Party Advisory
|
| Removed |
Reference Type |
https://news.ycombinator.com/item?id=39877267 Types: Issue Tracking
|
| Removed |
Reference Type |
https://openssf.org/blog/2024/03/30/xz-backdoor-cve-2024-3094/ Types: Third Party Advisory
|
| Removed |
Reference Type |
https://security-tracker.debian.org/tracker/CVE-2024-3094 Types: Third Party Advisory
|
| Removed |
Reference Type |
https://security.alpinelinux.org/vuln/CVE-2024-3094 Types: Third Party Advisory
|
| Removed |
Reference Type |
https://security.archlinux.org/CVE-2024-3094 Types: Third Party Advisory
|
| Removed |
Reference Type |
https://tukaani.org/xz-backdoor/ Types: Issue Tracking, Vendor Advisory
|
| Removed |
Reference Type |
https://twitter.com/LetsDefendIO/status/1774804387417751958 Types: Third Party Advisory
|
| Removed |
Reference Type |
https://twitter.com/debian/status/1774219194638409898 Types: Press/Media Coverage
|
| Removed |
Reference Type |
https://twitter.com/infosecb/status/1774595540233167206 Types: Press/Media Coverage
|
| Removed |
Reference Type |
https://twitter.com/infosecb/status/1774597228864139400 Types: Press/Media Coverage
|
| Removed |
Reference Type |
https://ubuntu.com/security/CVE-2024-3094 Types: Third Party Advisory
|
| Removed |
Reference Type |
https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094 Types: Third Party Advisory, US Government Resource
|
| Removed |
Reference Type |
https://www.darkreading.com/vulnerabilities-threats/are-you-affected-by-the-backdoor-in-xz-utils Types: Third Party Advisory
|
| Removed |
Reference Type |
https://www.tenable.com/blog/frequently-asked-questions-cve-2024-3094-supply-chain-backdoor-in-xz-utils Types: Third Party Advisory
|
| Removed |
Reference Type |
https://www.theregister.com/2024/03/29/malicious_backdoor_xz/ Types: Press/Media Coverage
|
| Removed |
Reference Type |
https://xeiaso.net/notes/2024/xz-vuln/ Types: Third Party Advisory
|
CVE Modified by CVE
11/21/2024 4:28:53 AM
| Action |
Type |
Old Value |
New Value |
| Added |
Reference |
http://www.openwall.com/lists/oss-security/2024/03/29/10
|
| Added |
Reference |
http://www.openwall.com/lists/oss-security/2024/03/29/12
|
| Added |
Reference |
http://www.openwall.com/lists/oss-security/2024/03/29/4
|
| Added |
Reference |
http://www.openwall.com/lists/oss-security/2024/03/29/5
|
| Added |
Reference |
http://www.openwall.com/lists/oss-security/2024/03/29/8
|
| Added |
Reference |
http://www.openwall.com/lists/oss-security/2024/03/30/12
|
| Added |
Reference |
http://www.openwall.com/lists/oss-security/2024/03/30/27
|
| Added |
Reference |
http://www.openwall.com/lists/oss-security/2024/03/30/36
|
| Added |
Reference |
http://www.openwall.com/lists/oss-security/2024/03/30/5
|
| Added |
Reference |
http://www.openwall.com/lists/oss-security/2024/04/16/5
|
| Added |
Reference |
https://access.redhat.com/security/cve/CVE-2024-3094
|
| Added |
Reference |
https://ariadne.space/2024/04/02/the-xz-utils-backdoor-is-a-symptom-of-a-larger-problem/
|
| Added |
Reference |
https://arstechnica.com/security/2024/03/backdoor-found-in-widely-used-linux-utility-breaks-encrypted-ssh-connections/
|
| Added |
Reference |
https://aws.amazon.com/security/security-bulletins/AWS-2024-002/
|
| Added |
Reference |
https://blog.netbsd.org/tnf/entry/statement_on_backdoor_in_xz
|
| Added |
Reference |
https://boehs.org/node/everything-i-know-about-the-xz-backdoor
|
| Added |
Reference |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024
|
| Added |
Reference |
https://bugs.gentoo.org/928134
|
| Added |
Reference |
https://bugzilla.redhat.com/show_bug.cgi?id=2272210
|
| Added |
Reference |
https://bugzilla.suse.com/show_bug.cgi?id=1222124
|
| Added |
Reference |
https://discourse.nixos.org/t/cve-2024-3094-malicious-code-in-xz-5-6-0-and-5-6-1-tarballs/42405
|
| Added |
Reference |
https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27
|
| Added |
Reference |
https://github.com/advisories/GHSA-rxwq-x6h5-x525
|
| Added |
Reference |
https://github.com/amlweems/xzbot
|
| Added |
Reference |
https://github.com/karcherm/xz-malware
|
| Added |
Reference |
https://gynvael.coldwind.pl/?lang=en&id=782
|
| Added |
Reference |
https://lists.debian.org/debian-security-announce/2024/msg00057.html
|
| Added |
Reference |
https://lists.freebsd.org/archives/freebsd-security/2024-March/000248.html
|
| Added |
Reference |
https://lwn.net/Articles/967180/
|
| Added |
Reference |
https://news.ycombinator.com/item?id=39865810
|
| Added |
Reference |
https://news.ycombinator.com/item?id=39877267
|
| Added |
Reference |
https://news.ycombinator.com/item?id=39895344
|
| Added |
Reference |
https://openssf.org/blog/2024/03/30/xz-backdoor-cve-2024-3094/
|
| Added |
Reference |
https://research.swtch.com/xz-script
|
| Added |
Reference |
https://research.swtch.com/xz-timeline
|
| Added |
Reference |
https://security-tracker.debian.org/tracker/CVE-2024-3094
|
| Added |
Reference |
https://security.alpinelinux.org/vuln/CVE-2024-3094
|
| Added |
Reference |
https://security.archlinux.org/CVE-2024-3094
|
| Added |
Reference |
https://security.netapp.com/advisory/ntap-20240402-0001/
|
| Added |
Reference |
https://tukaani.org/xz-backdoor/
|
| Added |
Reference |
https://twitter.com/LetsDefendIO/status/1774804387417751958
|
| Added |
Reference |
https://twitter.com/debian/status/1774219194638409898
|
| Added |
Reference |
https://twitter.com/infosecb/status/1774595540233167206
|
| Added |
Reference |
https://twitter.com/infosecb/status/1774597228864139400
|
| Added |
Reference |
https://ubuntu.com/security/CVE-2024-3094
|
| Added |
Reference |
https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094
|
| Added |
Reference |
https://www.darkreading.com/vulnerabilities-threats/are-you-affected-by-the-backdoor-in-xz-utils
|
| Added |
Reference |
https://www.kali.org/blog/about-the-xz-backdoor/
|
| Added |
Reference |
https://www.openwall.com/lists/oss-security/2024/03/29/4
|
| Added |
Reference |
https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users
|
| Added |
Reference |
https://www.tenable.com/blog/frequently-asked-questions-cve-2024-3094-supply-chain-backdoor-in-xz-utils
|
| Added |
Reference |
https://www.theregister.com/2024/03/29/malicious_backdoor_xz/
|
| Added |
Reference |
https://www.vicarius.io/vsociety/vulnerabilities/cve-2024-3094
|
| Added |
Reference |
https://xeiaso.net/notes/2024/xz-vuln/
|
CVE Modified by Red Hat, Inc.
5/14/2024 11:39:56 AM
| Action |
Type |
Old Value |
New Value |
CVE Modified by Red Hat, Inc.
5/01/2024 3:15:27 PM
| Action |
Type |
Old Value |
New Value |
| Added |
Reference |
Red Hat, Inc. http://www.openwall.com/lists/oss-security/2024/03/29/12 [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. http://www.openwall.com/lists/oss-security/2024/04/16/5 [No types assigned]
|
CVE Modified by Red Hat, Inc.
5/01/2024 2:15:24 PM
| Action |
Type |
Old Value |
New Value |
| Added |
Reference |
Red Hat, Inc. http://www.openwall.com/lists/oss-security/2024/03/29/10 [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. http://www.openwall.com/lists/oss-security/2024/03/29/4 [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. http://www.openwall.com/lists/oss-security/2024/03/29/5 [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. http://www.openwall.com/lists/oss-security/2024/03/29/8 [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. http://www.openwall.com/lists/oss-security/2024/03/30/27 [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. http://www.openwall.com/lists/oss-security/2024/03/30/36 [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. http://www.openwall.com/lists/oss-security/2024/03/30/5 [No types assigned]
|
CVE Modified by Red Hat, Inc.
5/01/2024 1:15:37 PM
| Action |
Type |
Old Value |
New Value |
| Added |
Reference |
Red Hat, Inc. http://www.openwall.com/lists/oss-security/2024/03/30/12 [No types assigned]
|
CVE Modified by Red Hat, Inc.
4/12/2024 3:15:08 AM
| Action |
Type |
Old Value |
New Value |
| Added |
Reference |
Red Hat, Inc. https://blog.netbsd.org/tnf/entry/statement_on_backdoor_in_xz [No types assigned]
|
CVE Modified by Red Hat, Inc.
4/03/2024 2:15:07 AM
| Action |
Type |
Old Value |
New Value |
| Added |
Reference |
Red Hat, Inc. https://ariadne.space/2024/04/02/the-xz-utils-backdoor-is-a-symptom-of-a-larger-problem/ [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://research.swtch.com/xz-script [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://research.swtch.com/xz-timeline [No types assigned]
|
CVE Modified by Red Hat, Inc.
4/03/2024 12:15:13 AM
| Action |
Type |
Old Value |
New Value |
| Added |
Reference |
Red Hat, Inc. https://www.kali.org/blog/about-the-xz-backdoor/ [No types assigned]
|
CVE Modified by Red Hat, Inc.
4/02/2024 7:15:54 PM
| Action |
Type |
Old Value |
New Value |
| Added |
Reference |
Red Hat, Inc. https://security.netapp.com/advisory/ntap-20240402-0001/ [No types assigned]
|
CVE Modified by Red Hat, Inc.
4/01/2024 2:15:08 PM
| Action |
Type |
Old Value |
New Value |
| Added |
Reference |
Red Hat, Inc. https://github.com/amlweems/xzbot [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://news.ycombinator.com/item?id=39895344 [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://www.vicarius.io/vsociety/vulnerabilities/cve-2024-3094 [No types assigned]
|
Initial Analysis by NIST
4/01/2024 1:23:05 PM
| Action |
Type |
Old Value |
New Value |
| Added |
CVSS V3.1 |
NIST AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
|
| Added |
CPE Configuration |
OR
*cpe:2.3:a:tukaani:xz:5.6.0:*:*:*:*:*:*:*
*cpe:2.3:a:tukaani:xz:5.6.1:*:*:*:*:*:*:*
|
| Changed |
Reference Type |
https://access.redhat.com/security/cve/CVE-2024-3094 No Types Assigned
|
https://access.redhat.com/security/cve/CVE-2024-3094 Vendor Advisory
|
| Changed |
Reference Type |
https://arstechnica.com/security/2024/03/backdoor-found-in-widely-used-linux-utility-breaks-encrypted-ssh-connections/ No Types Assigned
|
https://arstechnica.com/security/2024/03/backdoor-found-in-widely-used-linux-utility-breaks-encrypted-ssh-connections/ Third Party Advisory
|
| Changed |
Reference Type |
https://aws.amazon.com/security/security-bulletins/AWS-2024-002/ No Types Assigned
|
https://aws.amazon.com/security/security-bulletins/AWS-2024-002/ Third Party Advisory
|
| Changed |
Reference Type |
https://boehs.org/node/everything-i-know-about-the-xz-backdoor No Types Assigned
|
https://boehs.org/node/everything-i-know-about-the-xz-backdoor Third Party Advisory
|
| Changed |
Reference Type |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024 No Types Assigned
|
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024 Mailing List, Vendor Advisory
|
| Changed |
Reference Type |
https://bugs.gentoo.org/928134 No Types Assigned
|
https://bugs.gentoo.org/928134 Issue Tracking, Third Party Advisory
|
| Changed |
Reference Type |
https://bugzilla.redhat.com/show_bug.cgi?id=2272210 No Types Assigned
|
https://bugzilla.redhat.com/show_bug.cgi?id=2272210 Issue Tracking, Vendor Advisory
|
| Changed |
Reference Type |
https://bugzilla.suse.com/show_bug.cgi?id=1222124 No Types Assigned
|
https://bugzilla.suse.com/show_bug.cgi?id=1222124 Issue Tracking, Third Party Advisory
|
| Changed |
Reference Type |
https://discourse.nixos.org/t/cve-2024-3094-malicious-code-in-xz-5-6-0-and-5-6-1-tarballs/42405 No Types Assigned
|
https://discourse.nixos.org/t/cve-2024-3094-malicious-code-in-xz-5-6-0-and-5-6-1-tarballs/42405 Third Party Advisory
|
| Changed |
Reference Type |
https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27 No Types Assigned
|
https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27 Third Party Advisory
|
| Changed |
Reference Type |
https://github.com/advisories/GHSA-rxwq-x6h5-x525 No Types Assigned
|
https://github.com/advisories/GHSA-rxwq-x6h5-x525 Third Party Advisory
|
| Changed |
Reference Type |
https://github.com/karcherm/xz-malware No Types Assigned
|
https://github.com/karcherm/xz-malware Third Party Advisory
|
| Changed |
Reference Type |
https://gynvael.coldwind.pl/?lang=en&id=782 No Types Assigned
|
https://gynvael.coldwind.pl/?lang=en&id=782 Technical Description, Third Party Advisory
|
| Changed |
Reference Type |
https://lists.debian.org/debian-security-announce/2024/msg00057.html No Types Assigned
|
https://lists.debian.org/debian-security-announce/2024/msg00057.html Mailing List, Third Party Advisory
|
| Changed |
Reference Type |
https://lists.freebsd.org/archives/freebsd-security/2024-March/000248.html No Types Assigned
|
https://lists.freebsd.org/archives/freebsd-security/2024-March/000248.html Third Party Advisory
|
| Changed |
Reference Type |
https://lwn.net/Articles/967180/ No Types Assigned
|
https://lwn.net/Articles/967180/ Issue Tracking, Third Party Advisory
|
| Changed |
Reference Type |
https://news.ycombinator.com/item?id=39865810 No Types Assigned
|
https://news.ycombinator.com/item?id=39865810 Issue Tracking, Third Party Advisory
|
| Changed |
Reference Type |
https://news.ycombinator.com/item?id=39877267 No Types Assigned
|
https://news.ycombinator.com/item?id=39877267 Issue Tracking
|
| Changed |
Reference Type |
https://openssf.org/blog/2024/03/30/xz-backdoor-cve-2024-3094/ No Types Assigned
|
https://openssf.org/blog/2024/03/30/xz-backdoor-cve-2024-3094/ Third Party Advisory
|
| Changed |
Reference Type |
https://security-tracker.debian.org/tracker/CVE-2024-3094 No Types Assigned
|
https://security-tracker.debian.org/tracker/CVE-2024-3094 Third Party Advisory
|
| Changed |
Reference Type |
https://security.alpinelinux.org/vuln/CVE-2024-3094 No Types Assigned
|
https://security.alpinelinux.org/vuln/CVE-2024-3094 Third Party Advisory
|
| Changed |
Reference Type |
https://security.archlinux.org/CVE-2024-3094 No Types Assigned
|
https://security.archlinux.org/CVE-2024-3094 Third Party Advisory
|
| Changed |
Reference Type |
https://tukaani.org/xz-backdoor/ No Types Assigned
|
https://tukaani.org/xz-backdoor/ Issue Tracking, Vendor Advisory
|
| Changed |
Reference Type |
https://twitter.com/LetsDefendIO/status/1774804387417751958 No Types Assigned
|
https://twitter.com/LetsDefendIO/status/1774804387417751958 Third Party Advisory
|
| Changed |
Reference Type |
https://twitter.com/debian/status/1774219194638409898 No Types Assigned
|
https://twitter.com/debian/status/1774219194638409898 Press/Media Coverage
|
| Changed |
Reference Type |
https://twitter.com/infosecb/status/1774595540233167206 No Types Assigned
|
https://twitter.com/infosecb/status/1774595540233167206 Press/Media Coverage
|
| Changed |
Reference Type |
https://twitter.com/infosecb/status/1774597228864139400 No Types Assigned
|
https://twitter.com/infosecb/status/1774597228864139400 Press/Media Coverage
|
| Changed |
Reference Type |
https://ubuntu.com/security/CVE-2024-3094 No Types Assigned
|
https://ubuntu.com/security/CVE-2024-3094 Third Party Advisory
|
| Changed |
Reference Type |
https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094 No Types Assigned
|
https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094 Third Party Advisory, US Government Resource
|
| Changed |
Reference Type |
https://www.darkreading.com/vulnerabilities-threats/are-you-affected-by-the-backdoor-in-xz-utils No Types Assigned
|
https://www.darkreading.com/vulnerabilities-threats/are-you-affected-by-the-backdoor-in-xz-utils Third Party Advisory
|
| Changed |
Reference Type |
https://www.openwall.com/lists/oss-security/2024/03/29/4 No Types Assigned
|
https://www.openwall.com/lists/oss-security/2024/03/29/4 Mailing List
|
| Changed |
Reference Type |
https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users No Types Assigned
|
https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users Vendor Advisory
|
| Changed |
Reference Type |
https://www.tenable.com/blog/frequently-asked-questions-cve-2024-3094-supply-chain-backdoor-in-xz-utils No Types Assigned
|
https://www.tenable.com/blog/frequently-asked-questions-cve-2024-3094-supply-chain-backdoor-in-xz-utils Third Party Advisory
|
| Changed |
Reference Type |
https://www.theregister.com/2024/03/29/malicious_backdoor_xz/ No Types Assigned
|
https://www.theregister.com/2024/03/29/malicious_backdoor_xz/ Press/Media Coverage
|
| Changed |
Reference Type |
https://xeiaso.net/notes/2024/xz-vuln/ No Types Assigned
|
https://xeiaso.net/notes/2024/xz-vuln/ Third Party Advisory
|
CVE Modified by Red Hat, Inc.
4/01/2024 1:15:47 PM
| Action |
Type |
Old Value |
New Value |
| Added |
Reference |
Red Hat, Inc. https://twitter.com/LetsDefendIO/status/1774804387417751958 [No types assigned]
|
CVE Modified by Red Hat, Inc.
4/01/2024 1:15:08 AM
| Action |
Type |
Old Value |
New Value |
| Added |
Reference |
Red Hat, Inc. https://boehs.org/node/everything-i-know-about-the-xz-backdoor [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024 [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://bugs.gentoo.org/928134 [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://discourse.nixos.org/t/cve-2024-3094-malicious-code-in-xz-5-6-0-and-5-6-1-tarballs/42405 [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27 [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://github.com/advisories/GHSA-rxwq-x6h5-x525 [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://github.com/karcherm/xz-malware [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://lists.debian.org/debian-security-announce/2024/msg00057.html [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://lwn.net/Articles/967180/ [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://tukaani.org/xz-backdoor/ [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://twitter.com/debian/status/1774219194638409898 [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://twitter.com/infosecb/status/1774595540233167206 [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://twitter.com/infosecb/status/1774597228864139400 [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://ubuntu.com/security/CVE-2024-3094 [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://xeiaso.net/notes/2024/xz-vuln/ [No types assigned]
|
CVE Modified by Red Hat, Inc.
3/30/2024 9:15:47 PM
| Action |
Type |
Old Value |
New Value |
| Added |
Reference |
Red Hat, Inc. https://gynvael.coldwind.pl/?lang=en&id=782 [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://news.ycombinator.com/item?id=39877267 [No types assigned]
|
CVE Modified by Red Hat, Inc.
3/30/2024 4:15:53 PM
| Action |
Type |
Old Value |
New Value |
| Added |
Reference |
Red Hat, Inc. https://lists.freebsd.org/archives/freebsd-security/2024-March/000248.html [No types assigned]
|
CVE Modified by Red Hat, Inc.
3/30/2024 7:15:50 AM
| Action |
Type |
Old Value |
New Value |
| Added |
Reference |
Red Hat, Inc. https://arstechnica.com/security/2024/03/backdoor-found-in-widely-used-linux-utility-breaks-encrypted-ssh-connections/ [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://aws.amazon.com/security/security-bulletins/AWS-2024-002/ [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://bugzilla.suse.com/show_bug.cgi?id=1222124 [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://news.ycombinator.com/item?id=39865810 [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://openssf.org/blog/2024/03/30/xz-backdoor-cve-2024-3094/ [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://security-tracker.debian.org/tracker/CVE-2024-3094 [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://security.alpinelinux.org/vuln/CVE-2024-3094 [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://security.archlinux.org/CVE-2024-3094 [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094 [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://www.darkreading.com/vulnerabilities-threats/are-you-affected-by-the-backdoor-in-xz-utils [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://www.tenable.com/blog/frequently-asked-questions-cve-2024-3094-supply-chain-backdoor-in-xz-utils [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://www.theregister.com/2024/03/29/malicious_backdoor_xz/ [No types assigned]
|
CVE Modified by Red Hat, Inc.
3/29/2024 3:15:41 PM
| Action |
Type |
Old Value |
New Value |
| Changed |
Description |
Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. The tarballs included extra .m4 files, which contained instructions for building with automake that did not exist in the repository. These instructions, through a series of complex obfuscations, extract a prebuilt object file from one of the test archives, which is then used to modify specific functions in the code while building the liblzma package. This issue results in liblzma being used by additional software, like sshd, to provide functionality that will be interpreted by the modified functions.
|
Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0.
Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.
|
New CVE Received from Red Hat, Inc.
3/29/2024 1:15:21 PM
| Action |
Type |
Old Value |
New Value |
| Added |
Description |
Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. The tarballs included extra .m4 files, which contained instructions for building with automake that did not exist in the repository. These instructions, through a series of complex obfuscations, extract a prebuilt object file from one of the test archives, which is then used to modify specific functions in the code while building the liblzma package. This issue results in liblzma being used by additional software, like sshd, to provide functionality that will be interpreted by the modified functions.
|
| Added |
CVSS V3.1 |
Red Hat, Inc. AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
|
| Added |
CWE |
Red Hat, Inc. CWE-506
|
| Added |
Reference |
Red Hat, Inc. https://access.redhat.com/security/cve/CVE-2024-3094 [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://bugzilla.redhat.com/show_bug.cgi?id=2272210 [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://www.openwall.com/lists/oss-security/2024/03/29/4 [No types assigned]
|
| Added |
Reference |
Red Hat, Inc. https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users [No types assigned]
|
Quick Info
CVE Dictionary Entry: CVE-2024-3094 NVD
Published Date: 03/29/2024 NVD
Last Modified: 06/17/2026
Source: Red Hat, Inc.
|