CVE-2024-3094

critical

Description

Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.

From the Tenable Blog

Frequently Asked Questions About CVE-2024-3094, A Backdoor in XZ Utils
Frequently Asked Questions About CVE-2024-3094, A Backdoor in XZ Utils

Published: 2024-03-29

Frequently asked questions about CVE-2024-3094, a supply-chain attack responsible for a backdoor in XZ Utils, a widely used library found in multiple Linux distributions.

References

https://github.com/Stavros65/fishnet-company-cve

https://github.com/mhicairo-hue/cs50-cybersecurity-final-project

https://github.com/Lpk124/CyberRisk-Intel

https://github.com/namegabevictoire01-sys/cs50-cybersecurity-final-project

https://github.com/Haojie-Corner/security-research-notes

https://github.com/neeraj-sharma-0/cve-rag

https://github.com/avidzcheetah/CVE-Triage-Patch-agent

https://github.com/mainfiji/layer8-security-incident-response

https://github.com/Preacher98/Report-XZ-Utils-CVE-2024-3094

https://github.com/KarAshutosh/cve-research-helper

https://github.com/x-cmd-build/xz

https://github.com/devashridatta-dotcom/srap-toolkit

https://github.com/rey11997/cvewatch

https://github.com/selflabbs/security-intel-mcp

https://github.com/Corvalon/lichen

https://github.com/ykrishhh/cve-pocs

https://github.com/Jeneidi/safedeps

https://github.com/PhinehasNarh/cve-research

https://github.com/wulongovo/sec-rag-toolkit

https://github.com/webappsgo/cvedex

https://github.com/badchars/supply-chain-mcp-server

https://github.com/Jashiker/threat-intel-gemma

https://github.com/Bryn018/Semantic-Backdoor-Detector

https://github.com/cemheren/quicksheet-cve-ext

https://github.com/Erik-Castro/DevSecurity

https://github.com/nnatsopoulos/xz-backdoor-research

https://github.com/sumit760/cve-exploitability

https://github.com/stevehenderson/lab_xz_backdoor

https://github.com/mez-0/vulnify

https://github.com/BrandoTyler/CVE-TriageTool

https://github.com/Maher-Bhatt/TOMMY

https://github.com/Aks2812/SecOps-HubV2

https://github.com/aislabs-ai/cve-rank

https://github.com/mlab-sh/mlab-cve

https://github.com/hershate/CVE-Lookup-skill

https://github.com/AaronGrillot98/devsecops-ai-triage-cli

https://github.com/AaronGrillot98/DevSecOps-AI-Triage-CLI

https://github.com/jmckee27/CVE-Dashboard

https://github.com/Manishadua/devsecops-daily

https://github.com/taqi2508f-ui/SECURE-OPS

https://github.com/imfht/shenlong-cve-mcp

https://github.com/robertdfrench/ifuncd-up

https://github.com/hashb00k/vulnerability-tracker-RSS

https://github.com/red-cars-io/cve-intelligence-mcp

https://github.com/gadievron/cve-diff

https://github.com/cyber-green/CVE_REPORT_2026

https://github.com/yrhelm/nikruvx

https://github.com/Metbcy/bomdrift

https://github.com/vichargrave/claude_cve

https://github.com/Noetheon/vuln-prioritizer-workbench

https://github.com/bhchou/security_advisor

https://github.com/millsks/nvd-cve-mcp-server

https://github.com/millsks/cve-mcp-server

https://github.com/0xBlackash/CVE-2024-3094

https://github.com/nextgensoumen/soc-pulse

https://github.com/Noetheon/vuln-prioritizer-cli

https://github.com/enchanter-ai/hydra

https://github.com/gtamir02-png/cve-ai-agentdashboard

https://github.com/user70616E6461/phantom-intel

https://github.com/SolidCode321/cve-exploit-mapper

https://github.com/h3raklez/CVE-2024-3094

https://github.com/isecwire/cve-watchdog

https://github.com/yashbarot/security-scanner

https://github.com/UPinar/contrastapi

https://github.com/NexusFang-tech/cve-explorer

https://github.com/greydoubt/xz

https://github.com/narayan-ghorpade/cve-security-analyzer

https://github.com/SamuelRedfern/CVE-Converter

https://github.com/NodeNestor/Sentinel

https://github.com/michalAshurov/writeup-CVE-2024-3094

https://github.com/zaryouhashraf/CVE-2024-3094

https://github.com/tcoatswo/cve-watch

https://github.com/peterstringer/cve-triage-agent

https://github.com/kamalsrini/sentinel-cve

https://github.com/Leegreen305/CVE-Threat-Intelligence-Tracker

https://github.com/thinkchainai/vulnerability-intelligence-mcp

https://github.com/gopichand458/mcp-server-cve-intel

https://github.com/Ol4dipo/Vulnerability-Mapper

https://github.com/botzero-net/enterprise-security-toolkit

https://github.com/hackura/xz-cve-2024-3094

https://github.com/xSou1d/RBT_cve_index

https://github.com/nikjohn7/VulnPulse

https://github.com/encikayelwhitehat-glitch/CVE-2024-3094

https://github.com/JanhaviSoni7/CVE-Timeline-Generation

https://github.com/Syedomershah99/CVE-semantic-IEEE

https://github.com/brkothari/cve-analyzer

https://github.com/grimmolf/redhat-cve-tools

https://github.com/B1ack4sh/Blackash-CVE-2024-3094

https://github.com/ThreatInsightsdev/CVE_Explainer

https://github.com/ThomRgn/xzutils_backdoor_obfuscation

https://github.com/M1lo25/CS50FinalProject

https://github.com/M1lo25/CS50Cybersecurity

https://github.com/Jenderal92/PoC-AutoSync

https://github.com/Titus-soc/-CVE-2024-3094-Vulnerability-Checker-Fixer-Public

https://github.com/marklechner/cvewb

https://github.com/mrk336/CVE-2024-3094

https://github.com/Ikram124/CVE-2024-3094-analysis

https://github.com/Dermot-lab/TryHack

https://github.com/24Owais/threat-intel-cve-2024-3094

https://github.com/hiitaro/CVE-Searcher

https://github.com/laxmikumari615/Linux---Security---Detect-and-Mitigate-CVE-2024-3094

https://github.com/PuddinCat/GithubRepoSpider

https://github.com/AsimCr/POC_Collecter_Bot

https://github.com/ltdenard/cve_lookup

https://github.com/janepierresgithub/CVEAnalysisRepository

https://github.com/CyberSecAI/cve_info_refs_crawler

https://github.com/XiaomingX/cve-2024-3094-xz-backdoor-exploit

https://github.com/orhun/flawz

https://github.com/badsectorlabs/ludus_xz_backdoor

https://github.com/crfearnworks/ansible-CVE-2024-3094

https://github.com/felipecosta09/cve-2024-3094

https://github.com/Bella-Bc/xz-backdoor-CVE-2024-3094-Check

https://github.com/r0binak/xzk8s

Details

Source: Mitre, NVD

Published: 2024-03-29

Updated: 2025-08-19

Named Vulnerability: xz-utils backdoorNamed Vulnerability: XZ Backdoor

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 10

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.85974

Vulnerability Watch

Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.

Vulnerability of Interest