{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2024-3094", "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "state": "PUBLISHED", "assignerShortName": "redhat", "dateReserved": "2024-03-29T15:38:13.249Z", "datePublished": "2024-03-29T16:51:12.588Z", "dateUpdated": "2026-08-04T07:05:54.671Z" }, "containers": { "cna": { "title": "Xz: malicious code in distributed source", "metrics": [ { "other": { "content": { "value": "Critical", "namespace": "https://access.redhat.com/security/updates/classification/" }, "type": "Red Hat severity rating" } }, { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 10, "baseSeverity": "CRITICAL", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "CHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS" } ], "descriptions": [ { "lang": "en", "value": "Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. \r\nThrough a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library." } ], "affected": [ { "versions": [ { "status": "affected", "version": "5.6.0" }, { "status": "affected", "version": "5.6.1" } ], "packageName": "xz", "collectionURL": "https://github.com/tukaani-project/xz", "defaultStatus": "unaffected" }, { "vendor": "Red Hat", "product": "Red Hat Enterprise Linux 10", "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "packageName": "xz", "defaultStatus": "unaffected", "cpes": [ "cpe:/o:redhat:enterprise_linux:10" ] }, { "vendor": "Red Hat", "product": "Red Hat Enterprise Linux 6", "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "packageName": "xz", "defaultStatus": "unaffected", "cpes": [ "cpe:/o:redhat:enterprise_linux:6" ] }, { "vendor": "Red Hat", "product": "Red Hat Enterprise Linux 7", "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "packageName": "xz", "defaultStatus": "unaffected", "cpes": [ "cpe:/o:redhat:enterprise_linux:7" ] }, { "vendor": "Red Hat", "product": "Red Hat Enterprise Linux 8", "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "packageName": "xz", "defaultStatus": "unaffected", "cpes": [ "cpe:/o:redhat:enterprise_linux:8" ] }, { "vendor": "Red Hat", "product": "Red Hat Enterprise Linux 9", "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "packageName": "xz", "defaultStatus": "unaffected", "cpes": [ "cpe:/o:redhat:enterprise_linux:9" ] }, { "vendor": "Red Hat", "product": "Red Hat JBoss Enterprise Application Platform 8", "collectionURL": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html", "packageName": "xz", "defaultStatus": "unaffected", "cpes": [ "cpe:/a:redhat:jboss_enterprise_application_platform:8" ] } ], "references": [ { "url": "https://access.redhat.com/security/cve/CVE-2024-3094", "tags": [ "vdb-entry", "x_refsource_REDHAT" ] }, { "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2272210", "name": "RHBZ#2272210", "tags": [ "issue-tracking", "x_refsource_REDHAT" ] }, { "url": "https://www.openwall.com/lists/oss-security/2024/03/29/4" }, { "url": "https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users" } ], "datePublic": "2024-03-29T00:00:00.000Z", "problemTypes": [ { "descriptions": [ { "cweId": "CWE-506", "description": "Embedded Malicious Code", "lang": "en", "type": "CWE" } ] } ], "x_redhatCweChain": "CWE-506: Embedded Malicious Code", "timeline": [ { "lang": "en", "time": "2024-03-27T00:00:00.000Z", "value": "Reported to Red Hat." }, { "lang": "en", "time": "2024-03-29T00:00:00.000Z", "value": "Made public." } ], "credits": [ { "lang": "en", "value": "Red Hat would like to thank Andres Freund for reporting this issue." } ], "providerMetadata": { "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "shortName": "redhat", "dateUpdated": "2026-08-04T07:05:54.671Z" }, "x_generator": { "engine": "cvelib 1.8.0" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2024-04-02T04:00:23.138684Z", "id": "CVE-2024-3094", "options": [ { "Exploitation": "none" }, { "Automatable": "yes" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-07-30T15:37:17.662Z" } }, { "providerMetadata": { "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2025-08-19T00:24:09.962Z" }, "references": [ { "url": "https://www.binarly.io/blog/persistent-risk-xz-utils-backdoor-still-lurking-in-docker-images" }, { "tags": [ "vdb-entry", "x_refsource_REDHAT", "x_transferred" ], "url": "https://access.redhat.com/security/cve/CVE-2024-3094" }, { "tags": [ "x_transferred" ], "url": "https://ariadne.space/2024/04/02/the-xz-utils-backdoor-is-a-symptom-of-a-larger-problem/" }, { "tags": [ "x_transferred" ], "url": "https://arstechnica.com/security/2024/03/backdoor-found-in-widely-used-linux-utility-breaks-encrypted-ssh-connections/" }, { "tags": [ "x_transferred" ], "url": "https://aws.amazon.com/security/security-bulletins/AWS-2024-002/" }, { "tags": [ "x_transferred" ], "url": "https://blog.netbsd.org/tnf/entry/statement_on_backdoor_in_xz" }, { "tags": [ "x_transferred" ], "url": "https://boehs.org/node/everything-i-know-about-the-xz-backdoor" }, { "tags": [ "x_transferred" ], "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024" }, { "tags": [ "x_transferred" ], "url": "https://bugs.gentoo.org/928134" }, { "name": "RHBZ#2272210", "tags": [ "issue-tracking", "x_refsource_REDHAT", "x_transferred" ], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2272210" }, { "tags": [ "x_transferred" ], "url": "https://bugzilla.suse.com/show_bug.cgi?id=1222124" }, { "tags": [ "x_transferred" ], "url": "https://discourse.nixos.org/t/cve-2024-3094-malicious-code-in-xz-5-6-0-and-5-6-1-tarballs/42405" }, { "tags": [ "x_transferred" ], "url": "https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27" }, { "tags": [ "x_transferred" ], "url": "https://github.com/advisories/GHSA-rxwq-x6h5-x525" }, { "tags": [ "x_transferred" ], "url": "https://github.com/amlweems/xzbot" }, { "tags": [ "x_transferred" ], "url": "https://github.com/karcherm/xz-malware" }, { "tags": [ "x_transferred" ], "url": "https://gynvael.coldwind.pl/?lang=en&id=782" }, { "tags": [ "x_transferred" ], "url": "https://lists.debian.org/debian-security-announce/2024/msg00057.html" }, { "tags": [ "x_transferred" ], "url": "https://lists.freebsd.org/archives/freebsd-security/2024-March/000248.html" }, { "tags": [ "x_transferred" ], "url": "https://lwn.net/Articles/967180/" }, { "tags": [ "x_transferred" ], "url": "https://news.ycombinator.com/item?id=39865810" }, { "tags": [ "x_transferred" ], "url": "https://news.ycombinator.com/item?id=39877267" }, { "tags": [ "x_transferred" ], "url": "https://news.ycombinator.com/item?id=39895344" }, { "tags": [ "x_transferred" ], "url": "https://openssf.org/blog/2024/03/30/xz-backdoor-cve-2024-3094/" }, { "tags": [ "x_transferred" ], "url": "https://research.swtch.com/xz-script" }, { "tags": [ "x_transferred" ], "url": "https://research.swtch.com/xz-timeline" }, { "tags": [ "x_transferred" ], "url": "https://security-tracker.debian.org/tracker/CVE-2024-3094" }, { "tags": [ "x_transferred" ], "url": "https://security.alpinelinux.org/vuln/CVE-2024-3094" }, { "tags": [ "x_transferred" ], "url": "https://security.archlinux.org/CVE-2024-3094" }, { "tags": [ "x_transferred" ], "url": "https://security.netapp.com/advisory/ntap-20240402-0001/" }, { "tags": [ "x_transferred" ], "url": "https://tukaani.org/xz-backdoor/" }, { "tags": [ "x_transferred" ], "url": "https://twitter.com/LetsDefendIO/status/1774804387417751958" }, { "tags": [ "x_transferred" ], "url": "https://twitter.com/debian/status/1774219194638409898" }, { "tags": [ "x_transferred" ], "url": "https://twitter.com/infosecb/status/1774595540233167206" }, { "tags": [ "x_transferred" ], "url": "https://twitter.com/infosecb/status/1774597228864139400" }, { "tags": [ "x_transferred" ], "url": "https://ubuntu.com/security/CVE-2024-3094" }, { "tags": [ "x_transferred" ], "url": "https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094" }, { "tags": [ "x_transferred" ], "url": "https://www.darkreading.com/vulnerabilities-threats/are-you-affected-by-the-backdoor-in-xz-utils" }, { "tags": [ "x_transferred" ], "url": "https://www.kali.org/blog/about-the-xz-backdoor/" }, { "tags": [ "x_transferred" ], "url": "https://www.openwall.com/lists/oss-security/2024/03/29/4" }, { "tags": [ "x_transferred" ], "url": "https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users" }, { "tags": [ "x_transferred" ], "url": "https://www.tenable.com/blog/frequently-asked-questions-cve-2024-3094-supply-chain-backdoor-in-xz-utils" }, { "tags": [ "x_transferred" ], "url": "https://www.theregister.com/2024/03/29/malicious_backdoor_xz/" }, { "tags": [ "x_transferred" ], "url": "https://www.vicarius.io/vsociety/vulnerabilities/cve-2024-3094" }, { "tags": [ "x_transferred" ], "url": "https://xeiaso.net/notes/2024/xz-vuln/" }, { "tags": [ "x_transferred" ], "url": "http://www.openwall.com/lists/oss-security/2024/03/30/12" }, { "tags": [ "x_transferred" ], "url": "http://www.openwall.com/lists/oss-security/2024/03/30/27" }, { "tags": [ "x_transferred" ], "url": "http://www.openwall.com/lists/oss-security/2024/03/29/12" }, { "tags": [ "x_transferred" ], "url": "http://www.openwall.com/lists/oss-security/2024/03/29/10" }, { "tags": [ "x_transferred" ], "url": "http://www.openwall.com/lists/oss-security/2024/03/30/36" }, { "tags": [ "x_transferred" ], "url": "http://www.openwall.com/lists/oss-security/2024/04/16/5" }, { "tags": [ "x_transferred" ], "url": "http://www.openwall.com/lists/oss-security/2024/03/29/8" }, { "tags": [ "x_transferred" ], "url": "http://www.openwall.com/lists/oss-security/2024/03/30/5" }, { "tags": [ "x_transferred" ], "url": "http://www.openwall.com/lists/oss-security/2024/03/29/5" }, { "tags": [ "x_transferred" ], "url": "http://www.openwall.com/lists/oss-security/2024/03/29/4" } ], "title": "CVE Program Container", "x_generator": { "engine": "ADPogram 0.0.1" } } ] } }