logo

XZ Utils SSHd Backdoor 

ID: f1f50460-6c33-51c7-8da0-dc89544b429e

STIX ID: report--f1f50460-6c33-51c7-8da0-dc89544b429e

Feed Name: Qualys Blog

Threat Score
90/100

Date Published: 2024-03-30

Date Updated: 2026-04-28

Author: Diksha Ojha

...
...

On March 29, 2024 a researcher disclosed a supply-chain backdoor in XZ Utils 5.6.0 and 5.6.1 (CVE-2024-3094, CVSS 10) where malicious M4 macro code in release tarballs can modify liblzma during build to interfere with sshd authentication and potentially allow remote unauthorized access; multiple distributions and installation/media images were impacted and guidance recommends reverting to earlier uncompromised XZ releases, applying distro-specific mitigations, and performing hunting/incident response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.