EXPLORE DIRECTORY
LAST SYNCHRONIZED: 2026-08-15TLP:CLEAR
vulnerabilitycritical
XZ Utils / liblzma Upstream Build Injection Backdoor
EXECUTIVE INTELLIGENCE SUMMARY
Historic multi-year supply chain backdoor inserted into xz/liblzma 5.6.0 and 5.6.1 designed to intercept OpenSSH daemon cryptographic verification routines on glibc-based systems.
Crafted over three years by a persona named Jia Tan through gradual maintainer trust accumulation. The payload modified the build configuration through disguised M4 macros and hidden test binary files, hooking the `RSA_public_decrypt` function in sshd to permit unauthenticated arbitrary command execution via customized SSH client certificates.
TECHNICAL EXPLOITATION MATRIX
CVSS v4.0 SCORE
10.0 / 10.0
CRITICAL BASE SEVERITY
EPSS EXPLOIT PROBABILITY
81.2%
PERCENTILE 98.4
EXPLOITED IN THE WILD
NO KNOWN
CISA KEV CATALOG
AFFECTED SOFTWARE BUILDS
xz-utils / liblzma (Tukaani Project / Open Source)
AFFECTED: 5.6.0, 5.6.1
FIXED IN: 5.4.6 / 5.6.2 (clean)
RECOMMENDED REMEDIATION & MITIGATIONS
- [1]Downgrade xz-utils to trusted 5.4.x releases immediately on all Linux distributions.
- [2]Audit build system reproducible artifact hashing across all upstream open source dependencies.
SOURCE CITATIONS & ATTESTATIONS (1)
oss-security mailing list disclosureOpenwall
backdoor in upstream xz/liblzma leading to sshd auth bypass
TELEMETRY CARDID: cve-2024-3094
ENTITY TYPE
vulnerability
INDEXED TAGS
#supply_chain#openssh#xz_utils#backdoor#historical_milestone
CONNECTED ENTITIES (2)VIEW IN GRAPH →