Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.
Published: 2024-03-29
Frequently asked questions about CVE-2024-3094, a supply-chain attack responsible for a backdoor in XZ Utils, a widely used library found in multiple Linux distributions.
https://www.darkreading.com/vulnerabilities-threats/xz-utils-backdoor-live-old-docker-images
https://thehackernews.com/2025/08/researchers-spot-xz-utils-backdoor-in.html
https://securelist.com/vulnerability-report-q1-2024/112554/
https://securelist.com/xz-backdoor-story-part-1/112354/
https://www.nytimes.com/2024/04/03/technology/prevent-cyberattack-linux.html
https://github.com/Stavros65/fishnet-company-cve
https://github.com/mhicairo-hue/cs50-cybersecurity-final-project
https://github.com/Lpk124/CyberRisk-Intel
https://github.com/namegabevictoire01-sys/cs50-cybersecurity-final-project
https://github.com/Haojie-Corner/security-research-notes
https://github.com/neeraj-sharma-0/cve-rag
https://github.com/avidzcheetah/CVE-Triage-Patch-agent
https://github.com/mainfiji/layer8-security-incident-response
https://github.com/Preacher98/Report-XZ-Utils-CVE-2024-3094
https://github.com/KarAshutosh/cve-research-helper
https://github.com/x-cmd-build/xz
https://github.com/devashridatta-dotcom/srap-toolkit
https://github.com/rey11997/cvewatch
https://github.com/selflabbs/security-intel-mcp
https://github.com/Corvalon/lichen
https://github.com/ykrishhh/cve-pocs
https://github.com/Jeneidi/safedeps
https://github.com/PhinehasNarh/cve-research
https://github.com/wulongovo/sec-rag-toolkit
https://github.com/webappsgo/cvedex
https://github.com/badchars/supply-chain-mcp-server
https://github.com/Jashiker/threat-intel-gemma
https://github.com/Bryn018/Semantic-Backdoor-Detector
https://github.com/cemheren/quicksheet-cve-ext
https://github.com/Erik-Castro/DevSecurity
https://github.com/nnatsopoulos/xz-backdoor-research
https://github.com/sumit760/cve-exploitability
https://github.com/stevehenderson/lab_xz_backdoor
https://github.com/mez-0/vulnify
https://github.com/BrandoTyler/CVE-TriageTool
https://github.com/Maher-Bhatt/TOMMY
https://github.com/Aks2812/SecOps-HubV2
https://github.com/aislabs-ai/cve-rank
https://github.com/mlab-sh/mlab-cve
https://github.com/hershate/CVE-Lookup-skill
https://github.com/AaronGrillot98/devsecops-ai-triage-cli
https://github.com/AaronGrillot98/DevSecOps-AI-Triage-CLI
https://github.com/jmckee27/CVE-Dashboard
https://github.com/Manishadua/devsecops-daily
https://github.com/taqi2508f-ui/SECURE-OPS
https://github.com/imfht/shenlong-cve-mcp
https://github.com/robertdfrench/ifuncd-up
https://github.com/hashb00k/vulnerability-tracker-RSS
https://github.com/red-cars-io/cve-intelligence-mcp
https://github.com/gadievron/cve-diff
https://github.com/cyber-green/CVE_REPORT_2026
https://github.com/yrhelm/nikruvx
https://github.com/Metbcy/bomdrift
https://github.com/vichargrave/claude_cve
https://github.com/Noetheon/vuln-prioritizer-workbench
https://github.com/bhchou/security_advisor
https://github.com/millsks/nvd-cve-mcp-server
https://github.com/millsks/cve-mcp-server
https://github.com/0xBlackash/CVE-2024-3094
https://github.com/nextgensoumen/soc-pulse
https://github.com/Noetheon/vuln-prioritizer-cli
https://github.com/enchanter-ai/hydra
https://github.com/gtamir02-png/cve-ai-agentdashboard
https://github.com/user70616E6461/phantom-intel
https://github.com/SolidCode321/cve-exploit-mapper
https://github.com/h3raklez/CVE-2024-3094
https://github.com/isecwire/cve-watchdog
https://github.com/yashbarot/security-scanner
https://github.com/UPinar/contrastapi
https://github.com/NexusFang-tech/cve-explorer
https://github.com/greydoubt/xz
https://github.com/narayan-ghorpade/cve-security-analyzer
https://github.com/SamuelRedfern/CVE-Converter
https://github.com/NodeNestor/Sentinel
https://github.com/michalAshurov/writeup-CVE-2024-3094
https://github.com/zaryouhashraf/CVE-2024-3094
https://github.com/tcoatswo/cve-watch
https://github.com/peterstringer/cve-triage-agent
https://github.com/kamalsrini/sentinel-cve
https://github.com/Leegreen305/CVE-Threat-Intelligence-Tracker
https://github.com/thinkchainai/vulnerability-intelligence-mcp
https://github.com/gopichand458/mcp-server-cve-intel
https://github.com/Ol4dipo/Vulnerability-Mapper
https://github.com/botzero-net/enterprise-security-toolkit
https://github.com/hackura/xz-cve-2024-3094
https://github.com/xSou1d/RBT_cve_index
https://github.com/nikjohn7/VulnPulse
https://github.com/encikayelwhitehat-glitch/CVE-2024-3094
https://github.com/JanhaviSoni7/CVE-Timeline-Generation
https://github.com/Syedomershah99/CVE-semantic-IEEE
https://github.com/brkothari/cve-analyzer
https://github.com/grimmolf/redhat-cve-tools
https://github.com/B1ack4sh/Blackash-CVE-2024-3094
https://github.com/ThreatInsightsdev/CVE_Explainer
https://github.com/ThomRgn/xzutils_backdoor_obfuscation
https://github.com/M1lo25/CS50FinalProject
https://github.com/M1lo25/CS50Cybersecurity
https://github.com/Jenderal92/PoC-AutoSync
https://github.com/Titus-soc/-CVE-2024-3094-Vulnerability-Checker-Fixer-Public
https://github.com/marklechner/cvewb
https://github.com/mrk336/CVE-2024-3094
https://github.com/Ikram124/CVE-2024-3094-analysis
https://github.com/Dermot-lab/TryHack
https://github.com/24Owais/threat-intel-cve-2024-3094
https://github.com/hiitaro/CVE-Searcher
https://github.com/laxmikumari615/Linux---Security---Detect-and-Mitigate-CVE-2024-3094
https://github.com/PuddinCat/GithubRepoSpider
https://github.com/AsimCr/POC_Collecter_Bot
https://github.com/ltdenard/cve_lookup
https://github.com/janepierresgithub/CVEAnalysisRepository
https://github.com/CyberSecAI/cve_info_refs_crawler
https://github.com/XiaomingX/cve-2024-3094-xz-backdoor-exploit
https://github.com/orhun/flawz
https://github.com/badsectorlabs/ludus_xz_backdoor
https://github.com/crfearnworks/ansible-CVE-2024-3094
https://github.com/felipecosta09/cve-2024-3094
Published: 2024-03-29
Updated: 2025-08-19
Named Vulnerability: xz-utils backdoorNamed Vulnerability: XZ Backdoor
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 10
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity: Critical
EPSS: 0.85974
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Interest