DEFCON 3 · ELEVATED OBSERVATORY STATUS
04:24:00 UTC
EXPLORE DIRECTORY
LAST SYNCHRONIZED: 2026-08-15
vulnerabilitycritical

XZ Utils / liblzma Upstream Build Injection Backdoor

EXECUTIVE INTELLIGENCE SUMMARY

Historic multi-year supply chain backdoor inserted into xz/liblzma 5.6.0 and 5.6.1 designed to intercept OpenSSH daemon cryptographic verification routines on glibc-based systems.

Crafted over three years by a persona named Jia Tan through gradual maintainer trust accumulation. The payload modified the build configuration through disguised M4 macros and hidden test binary files, hooking the `RSA_public_decrypt` function in sshd to permit unauthenticated arbitrary command execution via customized SSH client certificates.

TECHNICAL EXPLOITATION MATRIX
CVSS v4.0 SCORE
10.0 / 10.0
CRITICAL BASE SEVERITY
EPSS EXPLOIT PROBABILITY
81.2%
PERCENTILE 98.4
EXPLOITED IN THE WILD
NO KNOWN
CISA KEV CATALOG
AFFECTED SOFTWARE BUILDS
xz-utils / liblzma (Tukaani Project / Open Source)
AFFECTED: 5.6.0, 5.6.1
FIXED IN: 5.4.6 / 5.6.2 (clean)
RECOMMENDED REMEDIATION & MITIGATIONS
  • [1]Downgrade xz-utils to trusted 5.4.x releases immediately on all Linux distributions.
  • [2]Audit build system reproducible artifact hashing across all upstream open source dependencies.
SOURCE CITATIONS & ATTESTATIONS (1)
oss-security mailing list disclosureOpenwall

backdoor in upstream xz/liblzma leading to sshd auth bypass

TELEMETRY CARDID: cve-2024-3094
ENTITY TYPE
vulnerability
INDEXED TAGS
#supply_chain#openssh#xz_utils#backdoor#historical_milestone