logo

XZ Utils backdoor incident (Incident)

ID: f49e7c57-1c0f-5c0a-95ac-b2fae3d7dba1

STIX ID: report--f49e7c57-1c0f-5c0a-95ac-b2fae3d7dba1

Feed Name: Wiz Cloud Threat Landscape

Threat Score
70/100

Date Published: 2024-03-29

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

A backdoor was found in XZ Utils releases 5.6.0 and 5.6.1 (CVE-2024-3094) that, via an obfuscated build-time injection, produces a compromised liblzma library capable of enabling SSH authentication bypass on certain Linux distributions where libsystemd and OpenSSH interact; the malicious code is present in released tarballs (not the git repo) and appears designed to evade fuzzing detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.