PT-2024-2451 · Opensuse +3 · Opensuse +3

Andres Freund

·

Published

2024-03-29

·

Updated

2026-02-03

·

CVE-2024-3094

CVSS v3.1
10
VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions liblzma versions 5.6.0 through 5.6.1 xz Utils versions 5.6.0 through 5.6.1
Description A critical vulnerability (CVE-2024-3094) was discovered in the xz Utils data compression library, specifically in versions 5.6.0 and 5.6.1. This vulnerability is a supply chain compromise involving a backdoor inserted into the library. The backdoor allows for unauthorized remote access to systems by modifying the data interaction with the library, potentially enabling attackers to bypass SSH authentication. The malicious code was introduced through a series of complex obfuscations, including a prebuilt object file hidden within a test file in the source code. The vulnerability was discovered by a Microsoft engineer who noticed unusual delays in SSH connections. The impact of this vulnerability could have been widespread, affecting numerous Linux distributions and applications.
Recommendations Downgrade to a version prior to 5.6.0.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-02406
CVE-2024-3094
GHSA-RXWQ-X6H5-X525
OPENSUSE-SU-2024:14017-1
ROSA-SA-2024-2407
ROSA-SA-2024-2409

Affected Products

Debian
Fedora
Opensuse
Xz Utils