logo

The XZ Utils backdoor (CVE-2024-3094): Everything you need to know, and more

ID: 44baab36-0f65-5c20-99a8-2e50d659a1ef

STIX ID: report--44baab36-0f65-5c20-99a8-2e50d659a1ef

Feed Name: Datadog Security Labs

Threat Score
88/100

Date Published: 2024-04-03

Date Updated: 2026-04-27

...
...

On March 28, 2024 a backdoor was discovered in xz-utils (versions 5.6.0 and 5.6.1, CVE-2024-3094) that drops a malicious shared object causing sshd to load code that hijacks OpenSSL's RSA_public_decrypt and enables remote code execution when an attacker has a specific private SSH key; multiple Linux distributions shipped the backdoored package, detection scripts and advisories are cited, and the operation is described as sophisticated, multi-year, and likely state-sponsored.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.