XZ Utils backdoor
In February 2024, a malicious backdoor was introduced to the Linux build of the xz utility within the liblzma library in versions 5.6.0 and 5.6.1 by an account using the name "Jia Tan". The backdoor gives an attacker who possesses a specific Ed448 private key remote code execution through OpenSSH (a suite of secure networking utilities) on the affected Linux system. The issue has been given the Common Vulnerabilities and Exposures number CVE-2024-3094 and has been assigned a CVSS score of 10.0, the highest possible score.
XZ Utils backdoor - Wikipedia Jump to content From Wikipedia, the free encyclopedia Patched software backdoor XZ Utils backdoor Previous XZ logo contributed by Jia Tan CVE identifier CVE - 2024-3094 Date discovered On or before 27 March 2024 ; 2 years ago  ( 2024-03-27 ) [ 1 ] [ 2 ] Date of public disclosure 29 March 2024 ; 2 years ago  ( 2024-03-29 ) Date patched 29 March 2024 ; 2 years ago  ( 2024-03-29 ) [ a ] [ 3 ] Discoverer Andres Freund Affected software xz / liblzma library Website tukaani .org /xz-backdoor /
Explore this link on the map →saved by
related reading
- What we know about the xz Utils backdoor that almost infected the world - Ars Technicaarstechnica.com
- research!rsc: Timeline of the xz open source attackresearch.swtch.com
- Everything I Know About the XZ Backdoorboehs.org
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- Backdoor (computing) - Wikipediaen.wikipedia.org
- Security incident disclosure — July 2026huggingface.co
- The Dirty Pipe Vulnerability — The Dirty Pipe Vulnerability documentationdirtypipe.cm4all.com
- Zenbleedlock.cmpxchg8b.com
- GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blogwiz.io
- zlib - Wikipediaen.wikipedia.org
- Devlog ⚡ Zig Programming Languageziglang.org
- When Intrusions Don’t Align: A New Water Watering Hole and Oldsmar | Dragosdragos.com