XZ Utils CVE-2024-3094: A Tale of Broken Trust, Curious Persistence, and a Call to Action
ID: 11747b08-3754-5887-8fd9-a1bfbba8295c
STIX ID: report--11747b08-3754-5887-8fd9-a1bfbba8295c
Feed Name: HackerOne Blog
Threat Score
A backdoor (tracked as CVE-2024-3094) was discovered in XZ Utils (liblzma) versions 5.6.0 and 5.6.1, covertly embedded in XZ-format test tarballs by a contributor who had built trust over years; the backdoor could allow SSH authentication bypass and remote code execution on affected Linux systems, representing a high-risk supply-chain compromise that impacts distributors using those XZ versions and highlights the need for stronger open-source supply-chain protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
