logo

CVE-2024-3094 Unveiled: XZ Utils Compromise Sparks Security Alarm

ID: 8f27c087-f2c5-5daa-8022-77a9905cd470

STIX ID: report--8f27c087-f2c5-5daa-8022-77a9905cd470

Feed Name: Seqrite Blog

Threat Score
85/100

Date Published: 2024-04-11

Date Updated: 2026-04-30

Author: Vinay Kumar

...
...

A malicious backdoor was introduced into XZ Utils (liblzma) releases 5.6.0 and 5.6.1 (CVE-2024-3094) via a supply-chain compromise; during build/install the backdoor modifies the Makefile and compiles a liblzma that hooks OpenSSH's RSA_public_decrypt to allow pre-auth remote payload execution. Multiple Linux distributions shipped the vulnerable versions; vendors and distros have published updates and advisories and Quick Heal/Seqrite signatures are provided to detect the threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.