CVE-2024-3094

The xz-utils backdoor: a backdoor in the source tarballs, aimed at sshd

Not a mistake. Malicious code was placed in the release tarballs of xz over several versions by someone who had spent two years becoming a maintainer, and it was found by accident days before it would have reached stable distributions.

xz-utilsNot in CISA’s Known Exploited catalogueEPSS 86.0% chance of an attempt in 30 daysCVSS 10CWE-506CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

A fixed package version is available on 1 of the releases below. Each row names the version, and the section below it says when this does not apply to you at all.

One read-only command. No account, no agent, nothing changed.

What it actually is

The tarballs for xz 5.6.0 and 5.6.1 contained build machinery, absent from the git repository, that injected code into liblzma. On systems where sshd is linked against liblzma through systemd, that code hooked the routine used to verify keys.

What an attacker gets: Pre-authentication remote code execution on a machine running an sshd patched to link liblzma, for whoever held the matching private key. It was a backdoor with an owner, not an open door.

When it applies to you, and when it does not

An old package version and a real exposure are different things. These are the conditions this one needs.

  • Almost no stable release ever carried it. The affected versions were in rolling and testing distributions for a matter of weeks. The table below is nearly empty for exactly that reason, and that is the story rather than a gap in the data.
  • The payload also required a distribution that patches sshd to link liblzma, which is a Debian and Red Hat family practice rather than an upstream one.
  • It was caught by a developer investigating a half-second delay in ssh logins, not by any scanner, any signature or any audit.

Check your own server

Read-only, changes nothing
xz --version && dpkg-query -W -f='${Version}\n' xz-utils 2>/dev/null || rpm -q xz

Any 5.6.0 or 5.6.1 build from the affected window is the one to look for. Every supported release below is far from those versions.

The part worth remembering

The useful lesson is not a version number. It is that the compromise lived in the build system rather than the source, was contributed by a trusted maintainer, and was found by somebody noticing that a login felt slow.

Fixed package version, per distribution

From each distribution’s own advisory data, asked per release. A version here is the package version that carries the fix on that release, not the upstream release number.

ReleaseSource packageStateFixed in
Ubuntu 22.04 LTSxz-utilsNo advisory names itno advisory for this release names it
Ubuntu 24.04 LTSxz-utilsNo advisory names itno advisory for this release names it
Debian 12 (bookworm)xz-utilsNo advisory names itno advisory for this release names it
Debian 13 (trixie)xz-utilsFixed5.6.1+really5.4.5-1
Rocky Linux 9xzNo advisory names itno advisory for this release names it
AlmaLinux 9xzNo advisory names itno advisory for this release names it

Install the fix with apt update && apt install --only-upgrade xz-utils on Debian and Ubuntu, or dnf update xz on Rocky Linux and AlmaLinux. Restart whatever was using it afterwards: a patched file on disk is not a patched process in memory.

What SecAI has recorded about it

Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.

Recorded from nvd. Its weakness class is CWE-506, from NVD.

Read next

Check whether this vulnerability affects your Linux server

One read-only command, no account and no agent. It reads the installed package versions on your server and tells you which advisories apply to them, CVE-2024-3094 included. It changes nothing.