VOOZH about

URL: https://nvd.nist.gov/vuln/detail/CVE-2024-3094

⇱ NVD - CVE-2024-3094


  1. Vulnerabilities

CVE-2024-3094 Detail

Modified After Enrichment

This CVE record has been updated after NVD enrichment efforts were completed. Enrichment data supplied by the NVD may require amendment due to these changes.

Description

Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.


Metrics

NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 4.0 Severity and Vector Strings:

NVD assessment not yet provided.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [email protected].

URL Source(s) Tag(s)
http://www.openwall.com/lists/oss-security/2024/03/29/10 CVE
http://www.openwall.com/lists/oss-security/2024/03/29/12 CVE
http://www.openwall.com/lists/oss-security/2024/03/29/4 CVE
http://www.openwall.com/lists/oss-security/2024/03/29/5 CVE
http://www.openwall.com/lists/oss-security/2024/03/29/8 CVE
http://www.openwall.com/lists/oss-security/2024/03/30/12 CVE
http://www.openwall.com/lists/oss-security/2024/03/30/27 CVE
http://www.openwall.com/lists/oss-security/2024/03/30/36 CVE
http://www.openwall.com/lists/oss-security/2024/03/30/5 CVE
http://www.openwall.com/lists/oss-security/2024/04/16/5 CVE
https://access.redhat.com/security/cve/CVE-2024-3094 CVE, Inc., Red Hat Vendor Advisory 
https://ariadne.space/2024/04/02/the-xz-utils-backdoor-is-a-symptom-of-a-larger-problem/ CVE
https://arstechnica.com/security/2024/03/backdoor-found-in-widely-used-linux-utility-breaks-encrypted-ssh-connections/ CVE Third Party Advisory 
https://aws.amazon.com/security/security-bulletins/AWS-2024-002/ CVE Third Party Advisory 
https://blog.netbsd.org/tnf/entry/statement_on_backdoor_in_xz CVE
https://boehs.org/node/everything-i-know-about-the-xz-backdoor CVE Third Party Advisory 
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024 CVE Mailing List  Vendor Advisory 
https://bugs.gentoo.org/928134 CVE Issue Tracking  Third Party Advisory 
https://bugzilla.redhat.com/show_bug.cgi?id=2272210 CVE, Inc., Red Hat Issue Tracking  Vendor Advisory 
https://bugzilla.suse.com/show_bug.cgi?id=1222124 CVE Issue Tracking  Third Party Advisory 
https://discourse.nixos.org/t/cve-2024-3094-malicious-code-in-xz-5-6-0-and-5-6-1-tarballs/42405 CVE Third Party Advisory 
https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27 CVE Third Party Advisory 
https://github.com/advisories/GHSA-rxwq-x6h5-x525 CVE Third Party Advisory 
https://github.com/amlweems/xzbot CVE
https://github.com/karcherm/xz-malware CVE Third Party Advisory 
https://gynvael.coldwind.pl/?lang=en&id=782 CVE Technical Description  Third Party Advisory 
https://lists.debian.org/debian-security-announce/2024/msg00057.html CVE Mailing List  Third Party Advisory 
https://lists.freebsd.org/archives/freebsd-security/2024-March/000248.html CVE Third Party Advisory 
https://lwn.net/Articles/967180/ CVE Issue Tracking  Third Party Advisory 
https://news.ycombinator.com/item?id=39865810 CVE Issue Tracking  Third Party Advisory 
https://news.ycombinator.com/item?id=39877267 CVE Issue Tracking 
https://news.ycombinator.com/item?id=39895344 CVE
https://openssf.org/blog/2024/03/30/xz-backdoor-cve-2024-3094/ CVE Third Party Advisory 
https://research.swtch.com/xz-script CVE
https://research.swtch.com/xz-timeline CVE
https://security-tracker.debian.org/tracker/CVE-2024-3094 CVE Third Party Advisory 
https://security.alpinelinux.org/vuln/CVE-2024-3094 CVE Third Party Advisory 
https://security.archlinux.org/CVE-2024-3094 CVE Third Party Advisory 
https://security.netapp.com/advisory/ntap-20240402-0001/ CVE
https://tukaani.org/xz-backdoor/ CVE Issue Tracking  Vendor Advisory 
https://twitter.com/LetsDefendIO/status/1774804387417751958 CVE Third Party Advisory 
https://twitter.com/debian/status/1774219194638409898 CVE Press/Media Coverage 
https://twitter.com/infosecb/status/1774595540233167206 CVE Press/Media Coverage 
https://twitter.com/infosecb/status/1774597228864139400 CVE Press/Media Coverage 
https://ubuntu.com/security/CVE-2024-3094 CVE Third Party Advisory 
https://www.binarly.io/blog/persistent-risk-xz-utils-backdoor-still-lurking-in-docker-images CVE
https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094 CVE Third Party Advisory  US Government Resource 
https://www.darkreading.com/vulnerabilities-threats/are-you-affected-by-the-backdoor-in-xz-utils CVE Third Party Advisory 
https://www.kali.org/blog/about-the-xz-backdoor/ CVE
https://www.openwall.com/lists/oss-security/2024/03/29/4 CVE, Inc., Red Hat Mailing List 
https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users CVE, Inc., Red Hat Vendor Advisory 
https://www.tenable.com/blog/frequently-asked-questions-cve-2024-3094-supply-chain-backdoor-in-xz-utils CVE Third Party Advisory 
https://www.theregister.com/2024/03/29/malicious_backdoor_xz/ CVE Press/Media Coverage 
https://www.vicarius.io/vsociety/vulnerabilities/cve-2024-3094 CVE
https://xeiaso.net/notes/2024/xz-vuln/ CVE Third Party Advisory 

Weakness Enumeration

CWE-ID CWE Name Source
CWE-506 Embedded Malicious Code Red Hat, Inc.  

Known Affected Software Configurations Switch to CPE 2.2

CPEs loading, please wait.

Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.

Change History

22 change records found show changes

CVE Modified by CISA-ADP 6/17/2026 3:43:17 AM

Action Type Old Value New Value
Added SSVC
{"timestamp":"2024-04-02T04:00:23.138684Z","id":"CVE-2024-3094","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}


CVE Modified by Red Hat, Inc. 6/17/2026 3:43:17 AM

Action Type Old Value New Value
Added Affected
[{"defaultStatus":"unaffected","collectionURL":"https://github.com/tukaani-project/xz","packageName":"xz","versions":[{"version":"5.6.0","status":"affected"},{"version":"5.6.1","status":"affected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"xz","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 6","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"xz","cpes":["cpe:/o:redhat:enterprise_linux:6"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"xz","cpes":["cpe:/o:redhat:enterprise_linux:7"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"xz","cpes":["cpe:/o:redhat:enterprise_linux:8"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"xz","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/jbossnetwork/restricted/listSoftware.html","packageName":"xz","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8"]}]


CVE Modified by CVE 8/18/2025 9:15:57 PM

Action Type Old Value New Value
Added Reference
https://www.binarly.io/blog/persistent-risk-xz-utils-backdoor-still-lurking-in-docker-images


CVE Modified by Red Hat, Inc. 2/06/2025 4:15:10 AM

Action Type Old Value New Value
Removed Reference
http://www.openwall.com/lists/oss-security/2024/03/29/10


Removed Reference
http://www.openwall.com/lists/oss-security/2024/03/29/12


Removed Reference
http://www.openwall.com/lists/oss-security/2024/03/29/4


Removed Reference
http://www.openwall.com/lists/oss-security/2024/03/29/5


Removed Reference
http://www.openwall.com/lists/oss-security/2024/03/29/8


Removed Reference
http://www.openwall.com/lists/oss-security/2024/03/30/12


Removed Reference
http://www.openwall.com/lists/oss-security/2024/03/30/27


Removed Reference
http://www.openwall.com/lists/oss-security/2024/03/30/36


Removed Reference
http://www.openwall.com/lists/oss-security/2024/03/30/5


Removed Reference
http://www.openwall.com/lists/oss-security/2024/04/16/5


Removed Reference
https://ariadne.space/2024/04/02/the-xz-utils-backdoor-is-a-symptom-of-a-larger-problem/


Removed Reference
https://arstechnica.com/security/2024/03/backdoor-found-in-widely-used-linux-utility-breaks-encrypted-ssh-connections/


Removed Reference
https://aws.amazon.com/security/security-bulletins/AWS-2024-002/


Removed Reference
https://blog.netbsd.org/tnf/entry/statement_on_backdoor_in_xz


Removed Reference
https://boehs.org/node/everything-i-know-about-the-xz-backdoor


Removed Reference
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024


Removed Reference
https://bugs.gentoo.org/928134


Removed Reference
https://bugzilla.suse.com/show_bug.cgi?id=1222124


Removed Reference
https://discourse.nixos.org/t/cve-2024-3094-malicious-code-in-xz-5-6-0-and-5-6-1-tarballs/42405


Removed Reference
https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27


Removed Reference
https://github.com/advisories/GHSA-rxwq-x6h5-x525


Removed Reference
https://github.com/amlweems/xzbot


Removed Reference
https://github.com/karcherm/xz-malware


Removed Reference
https://gynvael.coldwind.pl/?lang=en&id=782


Removed Reference
https://lists.debian.org/debian-security-announce/2024/msg00057.html


Removed Reference
https://lists.freebsd.org/archives/freebsd-security/2024-March/000248.html


Removed Reference
https://lwn.net/Articles/967180/


Removed Reference
https://news.ycombinator.com/item?id=39865810


Removed Reference
https://news.ycombinator.com/item?id=39877267


Removed Reference
https://news.ycombinator.com/item?id=39895344


Removed Reference
https://openssf.org/blog/2024/03/30/xz-backdoor-cve-2024-3094/


Removed Reference
https://research.swtch.com/xz-script


Removed Reference
https://research.swtch.com/xz-timeline


Removed Reference
https://security-tracker.debian.org/tracker/CVE-2024-3094


Removed Reference
https://security.alpinelinux.org/vuln/CVE-2024-3094


Removed Reference
https://security.archlinux.org/CVE-2024-3094


Removed Reference
https://security.netapp.com/advisory/ntap-20240402-0001/


Removed Reference
https://tukaani.org/xz-backdoor/


Removed Reference
https://twitter.com/LetsDefendIO/status/1774804387417751958


Removed Reference
https://twitter.com/debian/status/1774219194638409898


Removed Reference
https://twitter.com/infosecb/status/1774595540233167206


Removed Reference
https://twitter.com/infosecb/status/1774597228864139400


Removed Reference
https://ubuntu.com/security/CVE-2024-3094


Removed Reference
https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094


Removed Reference
https://www.darkreading.com/vulnerabilities-threats/are-you-affected-by-the-backdoor-in-xz-utils


Removed Reference
https://www.kali.org/blog/about-the-xz-backdoor/


Removed Reference
https://www.tenable.com/blog/frequently-asked-questions-cve-2024-3094-supply-chain-backdoor-in-xz-utils


Removed Reference
https://www.theregister.com/2024/03/29/malicious_backdoor_xz/


Removed Reference
https://www.vicarius.io/vsociety/vulnerabilities/cve-2024-3094


Removed Reference
https://xeiaso.net/notes/2024/xz-vuln/


Removed Reference Type
https://arstechnica.com/security/2024/03/backdoor-found-in-widely-used-linux-utility-breaks-encrypted-ssh-connections/ Types: Third Party Advisory


Removed Reference Type
https://aws.amazon.com/security/security-bulletins/AWS-2024-002/ Types: Third Party Advisory


Removed Reference Type
https://boehs.org/node/everything-i-know-about-the-xz-backdoor Types: Third Party Advisory


Removed Reference Type
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024 Types: Mailing List, Vendor Advisory


Removed Reference Type
https://bugs.gentoo.org/928134 Types: Issue Tracking, Third Party Advisory


Removed Reference Type
https://bugzilla.suse.com/show_bug.cgi?id=1222124 Types: Issue Tracking, Third Party Advisory


Removed Reference Type
https://discourse.nixos.org/t/cve-2024-3094-malicious-code-in-xz-5-6-0-and-5-6-1-tarballs/42405 Types: Third Party Advisory


Removed Reference Type
https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27 Types: Third Party Advisory


Removed Reference Type
https://github.com/advisories/GHSA-rxwq-x6h5-x525 Types: Third Party Advisory


Removed Reference Type
https://github.com/karcherm/xz-malware Types: Third Party Advisory


Removed Reference Type
https://gynvael.coldwind.pl/?lang=en&id=782 Types: Technical Description, Third Party Advisory


Removed Reference Type
https://lists.debian.org/debian-security-announce/2024/msg00057.html Types: Mailing List, Third Party Advisory


Removed Reference Type
https://lists.freebsd.org/archives/freebsd-security/2024-March/000248.html Types: Third Party Advisory


Removed Reference Type
https://lwn.net/Articles/967180/ Types: Issue Tracking, Third Party Advisory


Removed Reference Type
https://news.ycombinator.com/item?id=39865810 Types: Issue Tracking, Third Party Advisory


Removed Reference Type
https://news.ycombinator.com/item?id=39877267 Types: Issue Tracking


Removed Reference Type
https://openssf.org/blog/2024/03/30/xz-backdoor-cve-2024-3094/ Types: Third Party Advisory


Removed Reference Type
https://security-tracker.debian.org/tracker/CVE-2024-3094 Types: Third Party Advisory


Removed Reference Type
https://security.alpinelinux.org/vuln/CVE-2024-3094 Types: Third Party Advisory


Removed Reference Type
https://security.archlinux.org/CVE-2024-3094 Types: Third Party Advisory


Removed Reference Type
https://tukaani.org/xz-backdoor/ Types: Issue Tracking, Vendor Advisory


Removed Reference Type
https://twitter.com/LetsDefendIO/status/1774804387417751958 Types: Third Party Advisory


Removed Reference Type
https://twitter.com/debian/status/1774219194638409898 Types: Press/Media Coverage


Removed Reference Type
https://twitter.com/infosecb/status/1774595540233167206 Types: Press/Media Coverage


Removed Reference Type
https://twitter.com/infosecb/status/1774597228864139400 Types: Press/Media Coverage


Removed Reference Type
https://ubuntu.com/security/CVE-2024-3094 Types: Third Party Advisory


Removed Reference Type
https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094 Types: Third Party Advisory, US Government Resource


Removed Reference Type
https://www.darkreading.com/vulnerabilities-threats/are-you-affected-by-the-backdoor-in-xz-utils Types: Third Party Advisory


Removed Reference Type
https://www.tenable.com/blog/frequently-asked-questions-cve-2024-3094-supply-chain-backdoor-in-xz-utils Types: Third Party Advisory


Removed Reference Type
https://www.theregister.com/2024/03/29/malicious_backdoor_xz/ Types: Press/Media Coverage


Removed Reference Type
https://xeiaso.net/notes/2024/xz-vuln/ Types: Third Party Advisory


CVE Modified by CVE 11/21/2024 4:28:53 AM

Action Type Old Value New Value
Added Reference
http://www.openwall.com/lists/oss-security/2024/03/29/10


Added Reference
http://www.openwall.com/lists/oss-security/2024/03/29/12


Added Reference
http://www.openwall.com/lists/oss-security/2024/03/29/4


Added Reference
http://www.openwall.com/lists/oss-security/2024/03/29/5


Added Reference
http://www.openwall.com/lists/oss-security/2024/03/29/8


Added Reference
http://www.openwall.com/lists/oss-security/2024/03/30/12


Added Reference
http://www.openwall.com/lists/oss-security/2024/03/30/27


Added Reference
http://www.openwall.com/lists/oss-security/2024/03/30/36


Added Reference
http://www.openwall.com/lists/oss-security/2024/03/30/5


Added Reference
http://www.openwall.com/lists/oss-security/2024/04/16/5


Added Reference
https://access.redhat.com/security/cve/CVE-2024-3094


Added Reference
https://ariadne.space/2024/04/02/the-xz-utils-backdoor-is-a-symptom-of-a-larger-problem/


Added Reference
https://arstechnica.com/security/2024/03/backdoor-found-in-widely-used-linux-utility-breaks-encrypted-ssh-connections/


Added Reference
https://aws.amazon.com/security/security-bulletins/AWS-2024-002/


Added Reference
https://blog.netbsd.org/tnf/entry/statement_on_backdoor_in_xz


Added Reference
https://boehs.org/node/everything-i-know-about-the-xz-backdoor


Added Reference
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024


Added Reference
https://bugs.gentoo.org/928134


Added Reference
https://bugzilla.redhat.com/show_bug.cgi?id=2272210


Added Reference
https://bugzilla.suse.com/show_bug.cgi?id=1222124


Added Reference
https://discourse.nixos.org/t/cve-2024-3094-malicious-code-in-xz-5-6-0-and-5-6-1-tarballs/42405


Added Reference
https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27


Added Reference
https://github.com/advisories/GHSA-rxwq-x6h5-x525


Added Reference
https://github.com/amlweems/xzbot


Added Reference
https://github.com/karcherm/xz-malware


Added Reference
https://gynvael.coldwind.pl/?lang=en&id=782


Added Reference
https://lists.debian.org/debian-security-announce/2024/msg00057.html


Added Reference
https://lists.freebsd.org/archives/freebsd-security/2024-March/000248.html


Added Reference
https://lwn.net/Articles/967180/


Added Reference
https://news.ycombinator.com/item?id=39865810


Added Reference
https://news.ycombinator.com/item?id=39877267


Added Reference
https://news.ycombinator.com/item?id=39895344


Added Reference
https://openssf.org/blog/2024/03/30/xz-backdoor-cve-2024-3094/


Added Reference
https://research.swtch.com/xz-script


Added Reference
https://research.swtch.com/xz-timeline


Added Reference
https://security-tracker.debian.org/tracker/CVE-2024-3094


Added Reference
https://security.alpinelinux.org/vuln/CVE-2024-3094


Added Reference
https://security.archlinux.org/CVE-2024-3094


Added Reference
https://security.netapp.com/advisory/ntap-20240402-0001/


Added Reference
https://tukaani.org/xz-backdoor/


Added Reference
https://twitter.com/LetsDefendIO/status/1774804387417751958


Added Reference
https://twitter.com/debian/status/1774219194638409898


Added Reference
https://twitter.com/infosecb/status/1774595540233167206


Added Reference
https://twitter.com/infosecb/status/1774597228864139400


Added Reference
https://ubuntu.com/security/CVE-2024-3094


Added Reference
https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094


Added Reference
https://www.darkreading.com/vulnerabilities-threats/are-you-affected-by-the-backdoor-in-xz-utils


Added Reference
https://www.kali.org/blog/about-the-xz-backdoor/


Added Reference
https://www.openwall.com/lists/oss-security/2024/03/29/4


Added Reference
https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users


Added Reference
https://www.tenable.com/blog/frequently-asked-questions-cve-2024-3094-supply-chain-backdoor-in-xz-utils


Added Reference
https://www.theregister.com/2024/03/29/malicious_backdoor_xz/


Added Reference
https://www.vicarius.io/vsociety/vulnerabilities/cve-2024-3094


Added Reference
https://xeiaso.net/notes/2024/xz-vuln/


CVE Modified by Red Hat, Inc. 5/14/2024 11:39:56 AM

Action Type Old Value New Value

CVE Modified by Red Hat, Inc. 5/01/2024 3:15:27 PM

Action Type Old Value New Value
Added Reference
Red Hat, Inc. http://www.openwall.com/lists/oss-security/2024/03/29/12 [No types assigned]


Added Reference
Red Hat, Inc. http://www.openwall.com/lists/oss-security/2024/04/16/5 [No types assigned]


CVE Modified by Red Hat, Inc. 5/01/2024 2:15:24 PM

Action Type Old Value New Value
Added Reference
Red Hat, Inc. http://www.openwall.com/lists/oss-security/2024/03/29/10 [No types assigned]


Added Reference
Red Hat, Inc. http://www.openwall.com/lists/oss-security/2024/03/29/4 [No types assigned]


Added Reference
Red Hat, Inc. http://www.openwall.com/lists/oss-security/2024/03/29/5 [No types assigned]


Added Reference
Red Hat, Inc. http://www.openwall.com/lists/oss-security/2024/03/29/8 [No types assigned]


Added Reference
Red Hat, Inc. http://www.openwall.com/lists/oss-security/2024/03/30/27 [No types assigned]


Added Reference
Red Hat, Inc. http://www.openwall.com/lists/oss-security/2024/03/30/36 [No types assigned]


Added Reference
Red Hat, Inc. http://www.openwall.com/lists/oss-security/2024/03/30/5 [No types assigned]


CVE Modified by Red Hat, Inc. 5/01/2024 1:15:37 PM

Action Type Old Value New Value
Added Reference
Red Hat, Inc. http://www.openwall.com/lists/oss-security/2024/03/30/12 [No types assigned]


CVE Modified by Red Hat, Inc. 4/12/2024 3:15:08 AM

Action Type Old Value New Value
Added Reference
Red Hat, Inc. https://blog.netbsd.org/tnf/entry/statement_on_backdoor_in_xz [No types assigned]


CVE Modified by Red Hat, Inc. 4/03/2024 2:15:07 AM

Action Type Old Value New Value
Added Reference
Red Hat, Inc. https://ariadne.space/2024/04/02/the-xz-utils-backdoor-is-a-symptom-of-a-larger-problem/ [No types assigned]


Added Reference
Red Hat, Inc. https://research.swtch.com/xz-script [No types assigned]


Added Reference
Red Hat, Inc. https://research.swtch.com/xz-timeline [No types assigned]


CVE Modified by Red Hat, Inc. 4/03/2024 12:15:13 AM

Action Type Old Value New Value
Added Reference
Red Hat, Inc. https://www.kali.org/blog/about-the-xz-backdoor/ [No types assigned]


CVE Modified by Red Hat, Inc. 4/02/2024 7:15:54 PM

Action Type Old Value New Value
Added Reference
Red Hat, Inc. https://security.netapp.com/advisory/ntap-20240402-0001/ [No types assigned]


CVE Modified by Red Hat, Inc. 4/01/2024 2:15:08 PM

Action Type Old Value New Value
Added Reference
Red Hat, Inc. https://github.com/amlweems/xzbot [No types assigned]


Added Reference
Red Hat, Inc. https://news.ycombinator.com/item?id=39895344 [No types assigned]


Added Reference
Red Hat, Inc. https://www.vicarius.io/vsociety/vulnerabilities/cve-2024-3094 [No types assigned]


Initial Analysis by NIST 4/01/2024 1:23:05 PM

Action Type Old Value New Value
Added CVSS V3.1
NIST AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H


Added CPE Configuration
OR
 *cpe:2.3:a:tukaani:xz:5.6.0:*:*:*:*:*:*:*
 *cpe:2.3:a:tukaani:xz:5.6.1:*:*:*:*:*:*:*


Changed Reference Type
https://access.redhat.com/security/cve/CVE-2024-3094 No Types Assigned


https://access.redhat.com/security/cve/CVE-2024-3094 Vendor Advisory


Changed Reference Type
https://arstechnica.com/security/2024/03/backdoor-found-in-widely-used-linux-utility-breaks-encrypted-ssh-connections/ No Types Assigned


https://arstechnica.com/security/2024/03/backdoor-found-in-widely-used-linux-utility-breaks-encrypted-ssh-connections/ Third Party Advisory


Changed Reference Type
https://aws.amazon.com/security/security-bulletins/AWS-2024-002/ No Types Assigned


https://aws.amazon.com/security/security-bulletins/AWS-2024-002/ Third Party Advisory


Changed Reference Type
https://boehs.org/node/everything-i-know-about-the-xz-backdoor No Types Assigned


https://boehs.org/node/everything-i-know-about-the-xz-backdoor Third Party Advisory


Changed Reference Type
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024 No Types Assigned


https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024 Mailing List, Vendor Advisory


Changed Reference Type
https://bugs.gentoo.org/928134 No Types Assigned


https://bugs.gentoo.org/928134 Issue Tracking, Third Party Advisory


Changed Reference Type
https://bugzilla.redhat.com/show_bug.cgi?id=2272210 No Types Assigned


https://bugzilla.redhat.com/show_bug.cgi?id=2272210 Issue Tracking, Vendor Advisory


Changed Reference Type
https://bugzilla.suse.com/show_bug.cgi?id=1222124 No Types Assigned


https://bugzilla.suse.com/show_bug.cgi?id=1222124 Issue Tracking, Third Party Advisory


Changed Reference Type
https://discourse.nixos.org/t/cve-2024-3094-malicious-code-in-xz-5-6-0-and-5-6-1-tarballs/42405 No Types Assigned


https://discourse.nixos.org/t/cve-2024-3094-malicious-code-in-xz-5-6-0-and-5-6-1-tarballs/42405 Third Party Advisory


Changed Reference Type
https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27 No Types Assigned


https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27 Third Party Advisory


Changed Reference Type
https://github.com/advisories/GHSA-rxwq-x6h5-x525 No Types Assigned


https://github.com/advisories/GHSA-rxwq-x6h5-x525 Third Party Advisory


Changed Reference Type
https://github.com/karcherm/xz-malware No Types Assigned


https://github.com/karcherm/xz-malware Third Party Advisory


Changed Reference Type
https://gynvael.coldwind.pl/?lang=en&id=782 No Types Assigned


https://gynvael.coldwind.pl/?lang=en&id=782 Technical Description, Third Party Advisory


Changed Reference Type
https://lists.debian.org/debian-security-announce/2024/msg00057.html No Types Assigned


https://lists.debian.org/debian-security-announce/2024/msg00057.html Mailing List, Third Party Advisory


Changed Reference Type
https://lists.freebsd.org/archives/freebsd-security/2024-March/000248.html No Types Assigned


https://lists.freebsd.org/archives/freebsd-security/2024-March/000248.html Third Party Advisory


Changed Reference Type
https://lwn.net/Articles/967180/ No Types Assigned


https://lwn.net/Articles/967180/ Issue Tracking, Third Party Advisory


Changed Reference Type
https://news.ycombinator.com/item?id=39865810 No Types Assigned


https://news.ycombinator.com/item?id=39865810 Issue Tracking, Third Party Advisory


Changed Reference Type
https://news.ycombinator.com/item?id=39877267 No Types Assigned


https://news.ycombinator.com/item?id=39877267 Issue Tracking


Changed Reference Type
https://openssf.org/blog/2024/03/30/xz-backdoor-cve-2024-3094/ No Types Assigned


https://openssf.org/blog/2024/03/30/xz-backdoor-cve-2024-3094/ Third Party Advisory


Changed Reference Type
https://security-tracker.debian.org/tracker/CVE-2024-3094 No Types Assigned


https://security-tracker.debian.org/tracker/CVE-2024-3094 Third Party Advisory


Changed Reference Type
https://security.alpinelinux.org/vuln/CVE-2024-3094 No Types Assigned


https://security.alpinelinux.org/vuln/CVE-2024-3094 Third Party Advisory


Changed Reference Type
https://security.archlinux.org/CVE-2024-3094 No Types Assigned


https://security.archlinux.org/CVE-2024-3094 Third Party Advisory


Changed Reference Type
https://tukaani.org/xz-backdoor/ No Types Assigned


https://tukaani.org/xz-backdoor/ Issue Tracking, Vendor Advisory


Changed Reference Type
https://twitter.com/LetsDefendIO/status/1774804387417751958 No Types Assigned


https://twitter.com/LetsDefendIO/status/1774804387417751958 Third Party Advisory


Changed Reference Type
https://twitter.com/debian/status/1774219194638409898 No Types Assigned


https://twitter.com/debian/status/1774219194638409898 Press/Media Coverage


Changed Reference Type
https://twitter.com/infosecb/status/1774595540233167206 No Types Assigned


https://twitter.com/infosecb/status/1774595540233167206 Press/Media Coverage


Changed Reference Type
https://twitter.com/infosecb/status/1774597228864139400 No Types Assigned


https://twitter.com/infosecb/status/1774597228864139400 Press/Media Coverage


Changed Reference Type
https://ubuntu.com/security/CVE-2024-3094 No Types Assigned


https://ubuntu.com/security/CVE-2024-3094 Third Party Advisory


Changed Reference Type
https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094 No Types Assigned


https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094 Third Party Advisory, US Government Resource


Changed Reference Type
https://www.darkreading.com/vulnerabilities-threats/are-you-affected-by-the-backdoor-in-xz-utils No Types Assigned


https://www.darkreading.com/vulnerabilities-threats/are-you-affected-by-the-backdoor-in-xz-utils Third Party Advisory


Changed Reference Type
https://www.openwall.com/lists/oss-security/2024/03/29/4 No Types Assigned


https://www.openwall.com/lists/oss-security/2024/03/29/4 Mailing List


Changed Reference Type
https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users No Types Assigned


https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users Vendor Advisory


Changed Reference Type
https://www.tenable.com/blog/frequently-asked-questions-cve-2024-3094-supply-chain-backdoor-in-xz-utils No Types Assigned


https://www.tenable.com/blog/frequently-asked-questions-cve-2024-3094-supply-chain-backdoor-in-xz-utils Third Party Advisory


Changed Reference Type
https://www.theregister.com/2024/03/29/malicious_backdoor_xz/ No Types Assigned


https://www.theregister.com/2024/03/29/malicious_backdoor_xz/ Press/Media Coverage


Changed Reference Type
https://xeiaso.net/notes/2024/xz-vuln/ No Types Assigned


https://xeiaso.net/notes/2024/xz-vuln/ Third Party Advisory


CVE Modified by Red Hat, Inc. 4/01/2024 1:15:47 PM

Action Type Old Value New Value
Added Reference
Red Hat, Inc. https://twitter.com/LetsDefendIO/status/1774804387417751958 [No types assigned]


CVE Modified by Red Hat, Inc. 4/01/2024 1:15:08 AM

Action Type Old Value New Value
Added Reference
Red Hat, Inc. https://boehs.org/node/everything-i-know-about-the-xz-backdoor [No types assigned]


Added Reference
Red Hat, Inc. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024 [No types assigned]


Added Reference
Red Hat, Inc. https://bugs.gentoo.org/928134 [No types assigned]


Added Reference
Red Hat, Inc. https://discourse.nixos.org/t/cve-2024-3094-malicious-code-in-xz-5-6-0-and-5-6-1-tarballs/42405 [No types assigned]


Added Reference
Red Hat, Inc. https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27 [No types assigned]


Added Reference
Red Hat, Inc. https://github.com/advisories/GHSA-rxwq-x6h5-x525 [No types assigned]


Added Reference
Red Hat, Inc. https://github.com/karcherm/xz-malware [No types assigned]


Added Reference
Red Hat, Inc. https://lists.debian.org/debian-security-announce/2024/msg00057.html [No types assigned]


Added Reference
Red Hat, Inc. https://lwn.net/Articles/967180/ [No types assigned]


Added Reference
Red Hat, Inc. https://tukaani.org/xz-backdoor/ [No types assigned]


Added Reference
Red Hat, Inc. https://twitter.com/debian/status/1774219194638409898 [No types assigned]


Added Reference
Red Hat, Inc. https://twitter.com/infosecb/status/1774595540233167206 [No types assigned]


Added Reference
Red Hat, Inc. https://twitter.com/infosecb/status/1774597228864139400 [No types assigned]


Added Reference
Red Hat, Inc. https://ubuntu.com/security/CVE-2024-3094 [No types assigned]


Added Reference
Red Hat, Inc. https://xeiaso.net/notes/2024/xz-vuln/ [No types assigned]


CVE Modified by Red Hat, Inc. 3/30/2024 9:15:47 PM

Action Type Old Value New Value
Added Reference
Red Hat, Inc. https://gynvael.coldwind.pl/?lang=en&id=782 [No types assigned]


Added Reference
Red Hat, Inc. https://news.ycombinator.com/item?id=39877267 [No types assigned]


CVE Modified by Red Hat, Inc. 3/30/2024 4:15:53 PM

Action Type Old Value New Value
Added Reference
Red Hat, Inc. https://lists.freebsd.org/archives/freebsd-security/2024-March/000248.html [No types assigned]


CVE Modified by Red Hat, Inc. 3/30/2024 7:15:50 AM

Action Type Old Value New Value
Added Reference
Red Hat, Inc. https://arstechnica.com/security/2024/03/backdoor-found-in-widely-used-linux-utility-breaks-encrypted-ssh-connections/ [No types assigned]


Added Reference
Red Hat, Inc. https://aws.amazon.com/security/security-bulletins/AWS-2024-002/ [No types assigned]


Added Reference
Red Hat, Inc. https://bugzilla.suse.com/show_bug.cgi?id=1222124 [No types assigned]


Added Reference
Red Hat, Inc. https://news.ycombinator.com/item?id=39865810 [No types assigned]


Added Reference
Red Hat, Inc. https://openssf.org/blog/2024/03/30/xz-backdoor-cve-2024-3094/ [No types assigned]


Added Reference
Red Hat, Inc. https://security-tracker.debian.org/tracker/CVE-2024-3094 [No types assigned]


Added Reference
Red Hat, Inc. https://security.alpinelinux.org/vuln/CVE-2024-3094 [No types assigned]


Added Reference
Red Hat, Inc. https://security.archlinux.org/CVE-2024-3094 [No types assigned]


Added Reference
Red Hat, Inc. https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094 [No types assigned]


Added Reference
Red Hat, Inc. https://www.darkreading.com/vulnerabilities-threats/are-you-affected-by-the-backdoor-in-xz-utils [No types assigned]


Added Reference
Red Hat, Inc. https://www.tenable.com/blog/frequently-asked-questions-cve-2024-3094-supply-chain-backdoor-in-xz-utils [No types assigned]


Added Reference
Red Hat, Inc. https://www.theregister.com/2024/03/29/malicious_backdoor_xz/ [No types assigned]


CVE Modified by Red Hat, Inc. 3/29/2024 3:15:41 PM

Action Type Old Value New Value
Changed Description
Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. The tarballs included extra .m4 files, which contained instructions for building with automake that did not exist in the repository. These instructions, through a series of complex obfuscations, extract a prebuilt object file from one of the test archives, which is then used to modify specific functions in the code while building the liblzma package. This issue results in liblzma being used by additional software, like sshd, to provide functionality that will be interpreted by the modified functions.


Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. 
Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.


New CVE Received from Red Hat, Inc. 3/29/2024 1:15:21 PM

Action Type Old Value New Value
Added Description
Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. The tarballs included extra .m4 files, which contained instructions for building with automake that did not exist in the repository. These instructions, through a series of complex obfuscations, extract a prebuilt object file from one of the test archives, which is then used to modify specific functions in the code while building the liblzma package. This issue results in liblzma being used by additional software, like sshd, to provide functionality that will be interpreted by the modified functions.


Added CVSS V3.1
Red Hat, Inc. AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H


Added CWE
Red Hat, Inc. CWE-506


Added Reference
Red Hat, Inc. https://access.redhat.com/security/cve/CVE-2024-3094 [No types assigned]


Added Reference
Red Hat, Inc. https://bugzilla.redhat.com/show_bug.cgi?id=2272210 [No types assigned]


Added Reference
Red Hat, Inc. https://www.openwall.com/lists/oss-security/2024/03/29/4 [No types assigned]


Added Reference
Red Hat, Inc. https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users [No types assigned]


Quick Info

CVE Dictionary Entry:
CVE-2024-3094
NVD Published Date:
03/29/2024
NVD Last Modified:
06/17/2026
Source:
Red Hat, Inc.