XZ Utils, Backdoor, CVE-2024-3094 (Critical) -DC-Oct2026-2787

Listen to this Post

CVE-2024-3094 is a critical software supply chain backdoor discovered in XZ Utils versions 5.6.0 and 5.6.1, the ubiquitous compression library shipped in nearly every Linux distribution. The malicious code was inserted into liblzma—the shared library component of xz-utils—by a trusted co-maintainer over a period of roughly two to three years of patient social engineering. The backdoor was deliberately concealed and incorporated into the binary during the RPM or DEB packaging process for x86-64 architecture, using gcc and gnu linker, under the guise of a “test” step. The malicious logic was never in version-controlled source that you would see with git log; anyone diffing the Git tree against upstream saw only innocuous test data. Only the tarball produced by make dist contained the wired-up build-to-host.m4 script.
The implant abused a transitive linkage created by systemd: OpenSSH on Debian and Fedora links against libsystemd for notification sockets, and libsystemd in turn links against liblzma for journal compression. Once loaded into the sshd address space, the implant used GNU IFUNC resolvers to redirect calls to RSA_public_decrypt inside OpenSSL to its own function. When sshd authenticated a public key, the hooked resolver inspected the certificate, extracted a payload from specific fields, and—if the payload was signed with an attacker-controlled ED448 key—executed commands via system() before authentication completed. This effectively created a remote, pre-auth code execution backdoor on any host that had loaded the compromised library and exposed sshd built against it. The backdoor was discovered on March 28, 2024, by Microsoft engineer Andres Freund, who noticed a 500 millisecond delay during SSH logins and half a watt of extra CPU load—not a formal audit. Red Hat issued CVE-2024-3094 with a CVSS of 10.0 the same day. The compromised package was distributed across several Linux distributions including Fedora, Debian, Kali Linux, openSUSE, Arch Linux, and various package managers like Homebrew and pkgsrc. Production LTS distributions were spared only by timing. The malicious code was hidden within test files and activated during the build process, modifying functions within the liblzma library. This backdoor could allow an attacker to bypass SSH authentication and gain root-level access.

DailyCVE Form:

Platform: Linux xz-utils
Version: 5.6.0, 5.6.1
Vulnerability : Supply-chain backdoor
Severity: Critical (CVSS 10.0)
date: 2024-03-29

Prediction: 2024-04-15 (patch date)

What Undercode Say:

Analytics:

Bash commands to detect affected versions:

`xz –version | grep -E ‘5\.6\.

'`</h2>


`dpkg -l | grep xz-utils | grep -E '5\.6\.[bash]'`
`rpm -qa | grep xz | grep -E '5\.6\.[bash]'`


<h2 class="f1b-anim" style="color:#3b82f6;border-left:4px solid #3b82f6;padding-left:12px;margin:22px 0 10px 0;font-weight:bold">Check if sshd links against liblzma:</h2>

<h2 class="f1b-anim" style="color:#3b82f6;border-left:4px solid #3b82f6;padding-left:12px;margin:22px 0 10px 0;font-weight:bold">`ldd $(which sshd) | grep lzma`</h2>

<h2 class="f1b-anim" style="color:#3b82f6;border-left:4px solid #3b82f6;padding-left:12px;margin:22px 0 10px 0;font-weight:bold">Check for the backdoor's presence in the system:</h2>

<h2 class="f1b-anim" style="color:#3b82f6;border-left:4px solid #3b82f6;padding-left:12px;margin:22px 0 10px 0;font-weight:bold">`grep -r 'JiaT75' /usr/share/doc/xz-utils/ 2>/dev/null`</h2>

<h2 class="f1b-anim" style="color:#3b82f6;border-left:4px solid #3b82f6;padding-left:12px;margin:22px 0 10px 0;font-weight:bold">`grep -r 'bad-3-corrupt_lzma2' /usr/src/ 2>/dev/null`</h2>

<h2 class="f1b-anim" style="color:#3b82f6;border-left:4px solid #3b82f6;padding-left:12px;margin:22px 0 10px 0;font-weight:bold">Exploit: (Educational Purposes!)</h2>

The backdoor intercepted RSA_public_decrypt via GNU IFUNC resolvers. An attacker with the private ED448 key could craft an SSH certificate containing a payload in specific fields, triggering command execution via system() before authentication. The following is a conceptual illustration of the hooking mechanism:
[bash]
// Simplified IFUNC resolver concept
static void resolve_rsa_decrypt(void) {
if (is_attacker_cert()) {
return (void )malicious_payload;
}
return (void )RSA_public_decrypt;
}

The payload was extracted from the certificate fields and executed if signed with the attacker-controlled ED448 key.

Protection: from this CVE

Downgrade to XZ Utils version 5.4.6 or earlier and remove all traces of compromised versions. If patching is delayed, isolate affected systems, restrict outbound SSH connectivity, and audit build logs. Treat all compiled/deployed systems as fully compromised and rebuild from trusted sources. Verify the integrity of xz-utils packages using distribution-provided checksums. Monitor for unusual SSH login delays or CPU spikes. Apply vendor patches immediately when available.

Impact:

Successful exploitation allows an attacker to bypass SSH authentication and execute arbitrary code with root-level privileges on affected systems. The backdoor could enable remote, pre-auth code execution, effectively compromising the single most security-critical network service on a Linux host. The incident highlights the risks associated with supply chain compromises in open-source software.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top