CVE-2024-3094
Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 86.0%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.
- CVSS 3.1
- 10.0 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 85.97% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-506
- Affected
- tukaani/xz
- Source
- secalert@redhat.com
References
- https://access.redhat.com/security/cve/CVE-2024-3094Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2272210Issue Tracking, Vendor Advisory
- https://www.openwall.com/lists/oss-security/2024/03/29/4Mailing List
- https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-usersVendor Advisory
- http://www.openwall.com/lists/oss-security/2024/03/29/10
- http://www.openwall.com/lists/oss-security/2024/03/29/12
- http://www.openwall.com/lists/oss-security/2024/03/29/4
- http://www.openwall.com/lists/oss-security/2024/03/29/5
- http://www.openwall.com/lists/oss-security/2024/03/29/8
- http://www.openwall.com/lists/oss-security/2024/03/30/12
- http://www.openwall.com/lists/oss-security/2024/03/30/27
- http://www.openwall.com/lists/oss-security/2024/03/30/36
- http://www.openwall.com/lists/oss-security/2024/03/30/5
- http://www.openwall.com/lists/oss-security/2024/04/16/5
- https://access.redhat.com/security/cve/CVE-2024-3094Vendor Advisory
- https://ariadne.space/2024/04/02/the-xz-utils-backdoor-is-a-symptom-of-a-larger-problem/
- https://arstechnica.com/security/2024/03/backdoor-found-in-widely-used-linux-utility-breaks-encrypted-ssh-connections/Third Party Advisory
- https://aws.amazon.com/security/security-bulletins/AWS-2024-002/Third Party Advisory
- https://blog.netbsd.org/tnf/entry/statement_on_backdoor_in_xz
- https://boehs.org/node/everything-i-know-about-the-xz-backdoorThird Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024Mailing List, Vendor Advisory
- https://bugs.gentoo.org/928134Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2272210Issue Tracking, Vendor Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1222124Issue Tracking, Third Party Advisory
- https://discourse.nixos.org/t/cve-2024-3094-malicious-code-in-xz-5-6-0-and-5-6-1-tarballs/42405Third Party Advisory
- https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27Third Party Advisory
- https://github.com/advisories/GHSA-rxwq-x6h5-x525Third Party Advisory
- https://github.com/amlweems/xzbot
- https://github.com/karcherm/xz-malwareThird Party Advisory
- https://gynvael.coldwind.pl/?lang=en&id=782Technical Description, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.