← Volver a CVEs
CVE-2024-3094
CRITICAL10.0
Descripcion
Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.
Detalles CVE
Puntuacion CVSS v3.110.0
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado3/29/2024
Ultima modificacion8/19/2025
Fuentenvd
Avistamientos honeypot0
Productos afectados
tukaani:xz
Debilidades (CWE)
CWE-506
Referencias
https://access.redhat.com/security/cve/CVE-2024-3094(secalert@redhat.com)
https://bugzilla.redhat.com/show_bug.cgi?id=2272210(secalert@redhat.com)
https://www.openwall.com/lists/oss-security/2024/03/29/4(secalert@redhat.com)
https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users(secalert@redhat.com)
http://www.openwall.com/lists/oss-security/2024/03/29/10(af854a3a-2127-422b-91ae-364da2661108)
http://www.openwall.com/lists/oss-security/2024/03/29/12(af854a3a-2127-422b-91ae-364da2661108)
http://www.openwall.com/lists/oss-security/2024/03/29/4(af854a3a-2127-422b-91ae-364da2661108)
http://www.openwall.com/lists/oss-security/2024/03/29/5(af854a3a-2127-422b-91ae-364da2661108)
http://www.openwall.com/lists/oss-security/2024/03/29/8(af854a3a-2127-422b-91ae-364da2661108)
http://www.openwall.com/lists/oss-security/2024/03/30/12(af854a3a-2127-422b-91ae-364da2661108)
http://www.openwall.com/lists/oss-security/2024/03/30/27(af854a3a-2127-422b-91ae-364da2661108)
http://www.openwall.com/lists/oss-security/2024/03/30/36(af854a3a-2127-422b-91ae-364da2661108)
http://www.openwall.com/lists/oss-security/2024/03/30/5(af854a3a-2127-422b-91ae-364da2661108)
http://www.openwall.com/lists/oss-security/2024/04/16/5(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/security/cve/CVE-2024-3094(af854a3a-2127-422b-91ae-364da2661108)
https://ariadne.space/2024/04/02/the-xz-utils-backdoor-is-a-symptom-of-a-larger-problem/(af854a3a-2127-422b-91ae-364da2661108)
https://arstechnica.com/security/2024/03/backdoor-found-in-widely-used-linux-utility-breaks-encrypted-ssh-connections/(af854a3a-2127-422b-91ae-364da2661108)
https://aws.amazon.com/security/security-bulletins/AWS-2024-002/(af854a3a-2127-422b-91ae-364da2661108)
https://blog.netbsd.org/tnf/entry/statement_on_backdoor_in_xz(af854a3a-2127-422b-91ae-364da2661108)
https://boehs.org/node/everything-i-know-about-the-xz-backdoor(af854a3a-2127-422b-91ae-364da2661108)
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024(af854a3a-2127-422b-91ae-364da2661108)
https://bugs.gentoo.org/928134(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.redhat.com/show_bug.cgi?id=2272210(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.suse.com/show_bug.cgi?id=1222124(af854a3a-2127-422b-91ae-364da2661108)
https://discourse.nixos.org/t/cve-2024-3094-malicious-code-in-xz-5-6-0-and-5-6-1-tarballs/42405(af854a3a-2127-422b-91ae-364da2661108)
https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/advisories/GHSA-rxwq-x6h5-x525(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/amlweems/xzbot(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/karcherm/xz-malware(af854a3a-2127-422b-91ae-364da2661108)
https://gynvael.coldwind.pl/?lang=en&id=782(af854a3a-2127-422b-91ae-364da2661108)
https://lists.debian.org/debian-security-announce/2024/msg00057.html(af854a3a-2127-422b-91ae-364da2661108)
https://lists.freebsd.org/archives/freebsd-security/2024-March/000248.html(af854a3a-2127-422b-91ae-364da2661108)
https://lwn.net/Articles/967180/(af854a3a-2127-422b-91ae-364da2661108)
https://news.ycombinator.com/item?id=39865810(af854a3a-2127-422b-91ae-364da2661108)
https://news.ycombinator.com/item?id=39877267(af854a3a-2127-422b-91ae-364da2661108)
https://news.ycombinator.com/item?id=39895344(af854a3a-2127-422b-91ae-364da2661108)
https://openssf.org/blog/2024/03/30/xz-backdoor-cve-2024-3094/(af854a3a-2127-422b-91ae-364da2661108)
https://research.swtch.com/xz-script(af854a3a-2127-422b-91ae-364da2661108)
https://research.swtch.com/xz-timeline(af854a3a-2127-422b-91ae-364da2661108)
https://security-tracker.debian.org/tracker/CVE-2024-3094(af854a3a-2127-422b-91ae-364da2661108)
https://security.alpinelinux.org/vuln/CVE-2024-3094(af854a3a-2127-422b-91ae-364da2661108)
https://security.archlinux.org/CVE-2024-3094(af854a3a-2127-422b-91ae-364da2661108)
https://security.netapp.com/advisory/ntap-20240402-0001/(af854a3a-2127-422b-91ae-364da2661108)
https://tukaani.org/xz-backdoor/(af854a3a-2127-422b-91ae-364da2661108)
https://twitter.com/LetsDefendIO/status/1774804387417751958(af854a3a-2127-422b-91ae-364da2661108)
https://twitter.com/debian/status/1774219194638409898(af854a3a-2127-422b-91ae-364da2661108)
https://twitter.com/infosecb/status/1774595540233167206(af854a3a-2127-422b-91ae-364da2661108)
https://twitter.com/infosecb/status/1774597228864139400(af854a3a-2127-422b-91ae-364da2661108)
https://ubuntu.com/security/CVE-2024-3094(af854a3a-2127-422b-91ae-364da2661108)
https://www.binarly.io/blog/persistent-risk-xz-utils-backdoor-still-lurking-in-docker-images(af854a3a-2127-422b-91ae-364da2661108)
https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094(af854a3a-2127-422b-91ae-364da2661108)
https://www.darkreading.com/vulnerabilities-threats/are-you-affected-by-the-backdoor-in-xz-utils(af854a3a-2127-422b-91ae-364da2661108)
https://www.kali.org/blog/about-the-xz-backdoor/(af854a3a-2127-422b-91ae-364da2661108)
https://www.openwall.com/lists/oss-security/2024/03/29/4(af854a3a-2127-422b-91ae-364da2661108)
https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users(af854a3a-2127-422b-91ae-364da2661108)
https://www.tenable.com/blog/frequently-asked-questions-cve-2024-3094-supply-chain-backdoor-in-xz-utils(af854a3a-2127-422b-91ae-364da2661108)
https://www.theregister.com/2024/03/29/malicious_backdoor_xz/(af854a3a-2127-422b-91ae-364da2661108)
https://www.vicarius.io/vsociety/vulnerabilities/cve-2024-3094(af854a3a-2127-422b-91ae-364da2661108)
https://xeiaso.net/notes/2024/xz-vuln/(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.