CVE-2024-3094: XZ Utils Backdoor
A deliberately planted backdoor in the xz compression library, inserted over roughly two years by a project co-maintainer who gained trust before sabotaging the build scripts. The backdoored liblzma intercepts and manipulates sshd's RSA key authentication on affected glibc-based Linux systems, giving an attacker with the right private key unauthenticated remote code execution. It was caught only because a developer noticed a small SSH login latency regression.
View the authoritative record on NVD ↗Affected software
- xz / liblzma 5.6.0 and 5.6.1
How it's exploited
On a system where the backdoored liblzma is linked into sshd (via libsystemd on certain distributions running bleeding-edge packages), send an SSH connection with a specially crafted certificate; the hijacked ifunc resolver diverts execution into attacker-controlled code before authentication completes.
Severity
CVE-2024-3094 carries a CVSS 3.1 base score of 10.0, rated Critical. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2024-3094 is categorized under CWE-506, the general weakness pattern behind this specific vulnerability.
Where this fits in a TurboPentest engagement
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Remediation
Downgrade to a known-clean xz/liblzma version (5.4.x or earlier) or apply the distribution's reverted package, and verify package checksums against upstream, since the backdoor was distributed only in the release tarballs, not the public git history.
Frequently asked questions
What is CVE-2024-3094?
A deliberately planted backdoor in the xz compression library, inserted over roughly two years by a project co-maintainer who gained trust before sabotaging the build scripts. The backdoored liblzma intercepts and manipulates sshd's RSA key authentication on affected glibc-based Linux systems, giving an attacker with the right private key unauthenticated remote code execution. It was caught only because a developer noticed a small SSH login latency regression.
How severe is CVE-2024-3094?
CVE-2024-3094 has a CVSS 3.1 base score of 10.0 out of 10, rated Critical.
What software is affected by CVE-2024-3094?
CVE-2024-3094 affects xz / liblzma 5.6.0 and 5.6.1.
How do you fix CVE-2024-3094?
Downgrade to a known-clean xz/liblzma version (5.4.x or earlier) or apply the distribution's reverted package, and verify package checksums against upstream, since the backdoor was distributed only in the release tarballs, not the public git history.
Where is the authoritative record for CVE-2024-3094?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2024-3094 at https://nvd.nist.gov/vuln/detail/CVE-2024-3094, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest