QID 379548

Date Published: 2024-03-30

QID 379548: XZ Utils SSH Backdoor Versions Detected (CVE-2024-3094)

Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.

Affected Software:
xz (xz-utils) versions 5.6.0, 5.6.1

QID Detection Logic (Authenticated):(Linux)
The QID checks the non package manager installations of xz, xz-utils version 5.6.0 and 5.6.1

The malicious code may allow unauthorized access to affected systems.

  • CVSS V3 rated as Critical - 10 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Vendors are suggesting to downgrade to 5.4.x. Refer to Red Hat Blog for more details.

    CVEs related to QID 379548

    Software Advisories
    Advisory ID Software Component Link