logo

Urgent: Secret Backdoor Found in XZ Utils Library, Impacts Major Linux Distros

ID: d90ca87d-2752-59f3-b385-2d76eb08cfea

STIX ID: report--d90ca87d-2752-59f3-b385-2d76eb08cfea

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-03-30

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Red Hat and other vendors alerted that XZ Utils versions 5.6.0 and 5.6.1 were backdoored (CVE-2024-3094, CVSS 10.0) via an obfuscated prebuilt object hidden in source commits, resulting in a modified liblzma that can intercept calls and potentially inject code into OpenSSH (sshd) to allow pre-auth remote payload execution; Fedora 41 and Rawhide packages are known impacted, GitHub disabled the repository, CISA issued guidance, and users are advised to downgrade to a known-good XZ version.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.