CVE-2024-3094 Vulnerability (XZ Backdoor) Discovered in Linux Data Compression Library

Red Hat issued an urgent security advisory on Friday regarding two versions of the widely used data compression tool XZ Utils, previously known as LZMA Utils, which have been compromised with malicious code aimed at unauthorized remote access.

The security flaw, identified as CVE-2024-3094 and rated with a severity score of 10.0, affects XZ Utils versions 5.6.0 (released on February 24) and 5.6.1 (released on March 9).

According to Red Hat, the compromised code within the liblzma library is injected via a complex process during the build, allowing interception and modification of data interactions. Specifically, the code aims to tamper with the sshd daemon process within the systemd software suite, potentially enabling unauthorized access to the system under certain conditions.

Backdoor Allows for Arbitrary Payloads Through SSH

The ultimate objective of this backdoor, as identified by JFrog, is to inject code into the OpenSSH server (SSHD) to allow specific remote attackers with a particular private key to execute arbitrary payloads through SSH before authentication, essentially taking control of the victim's machine.

The issue was brought to light by Microsoft security researcher Andres Freund, who identified heavily obfuscated malicious code introduced through a series of commits to the Tukaani Project's GitHub repository by a user named Jia Tan (JiaT75).

GitHub, owned by Microsoft, has taken action by disabling the XZ Utils repository due to a violation of its terms of service. As of now, there have been no reported instances of active exploitation in the wild.

The affected packages have been found only in Fedora 41 and Fedora Rawhide, with no impact on other distributions such as Alpine Linux, Amazon Linux, Debian Stable, Gentoo Linux, Linux Mint, Red Hat Enterprise Linux (RHEL), SUSE Linux Enterprise and Leap, and Ubuntu.

April 1, 2024
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.