CVE-2024-3094General(tukaani / xz)

CRITICALCVSS 10.0 · CRITICAL

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch tukaani xz systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-506

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • xz

Threat summary

  • Active exploitation appears in 6 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 98 mentions across 59 observed days

What's happening

  • Active exploitation reported across 6 signals
  • Exploit tool or code specified in 6 signals
  • PoC mentioned or linked in 9 signals
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 29 signals
  • General: 43 classified signals
  • Disclosure: 27 classified signals
  • Peaked 57d ago at 5 mentions (2026-02-02); latest day: 2
  • 98 total mentions across 59 days

Affected systems

Vendors
Products
xz

2 versions affected across 1 product

Deep dive

Activity timeline98 mentions / 59d
01345Mentions · 2026-01-28: 2Mentions · 2026-02-02: 5Mentions · 2026-02-03: 2Mentions · 2026-02-07: 3Mentions · 2026-02-08: 1Mentions · 2026-02-09: 1Mentions · 2026-02-26: 4Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Mentions · 2026-03-01: 1Mentions · 2026-03-02: 1Mentions · 2026-03-03: 1Mentions · 2026-03-04: 2Mentions · 2026-03-09: 1Mentions · 2026-03-10: 2Mentions · 2026-03-11: 2Mentions · 2026-03-21: 1Mentions · 2026-03-25: 3Mentions · 2026-03-26: 1Mentions · 2026-03-27: 2Mentions · 2026-03-28: 1Mentions · 2026-03-31: 2Mentions · 2026-04-01: 3Mentions · 2026-04-02: 1Mentions · 2026-04-08: 1Mentions · 2026-04-15: 1Mentions · 2026-05-08: 5Mentions · 2026-05-10: 1Mentions · 2026-05-31: 1Mentions · 2026-06-01: 1Mentions · 2026-06-04: 1Mentions · 2026-06-11: 1Mentions · 2026-06-17: 1Mentions · 2026-06-23: 2Mentions · 2026-06-24: 1Mentions · 2026-06-27: 1Mentions · 2026-07-12: 2Mentions · 2026-07-13: 1Mentions · 2026-07-20: 1Mentions · 2026-07-21: 1Mentions · 2026-07-28: 4Mentions · 2026-07-31: 1Mentions · 2026-08-03: 1Mentions · 2026-08-05: 1Mentions · 2026-08-12: 2Mentions · 2026-08-26: 1Mentions · 2026-09-08: 2Mentions · 2026-09-13: 1Mentions · 2026-09-14: 3Mentions · 2026-09-15: 1Mentions · 2026-09-16: 4Mentions · 2026-09-25: 1Mentions · 2026-09-26: 1Mentions · 2026-09-28: 1Mentions · 2026-09-30: 2Mentions · 2026-10-02: 1Mentions · 2026-10-06: 1Mentions · 2026-10-07: 2Mentions · 2026-10-08: 2PoC Mentioned / Linked · 2026-02-09: 1PoC Mentioned / Linked · 2026-05-08: 3PoC Mentioned / Linked · 2026-06-23: 1PoC Mentioned / Linked · 2026-07-20: 1PoC Mentioned / Linked · 2026-08-12: 1PoC Mentioned / Linked · 2026-09-08: 1PoC Mentioned / Linked · 2026-09-16: 1Exploit Tool / Code · 2026-05-08: 2Exploit Tool / Code · 2026-07-20: 1Exploit Tool / Code · 2026-08-12: 1Exploit Tool / Code · 2026-09-08: 1Exploit Tool / Code · 2026-09-16: 1Active Exploitation · 2026-02-09: 1Active Exploitation · 2026-02-26: 1Active Exploitation · 2026-02-28: 1Active Exploitation · 2026-03-31: 1Active Exploitation · 2026-04-01: 2Patch / Workaround · 2026-02-02: 1Patch / Workaround · 2026-02-09: 1Patch / Workaround · 2026-02-27: 1Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-04-01: 1Patch / Workaround · 2026-05-31: 1Technical Details · 2026-02-02: 3Technical Details · 2026-02-08: 1Technical Details · 2026-02-09: 1Technical Details · 2026-02-26: 3Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-01: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-25: 2Technical Details · 2026-03-27: 2Technical Details · 2026-03-28: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-08: 1Technical Details · 2026-05-10: 1Technical Details · 2026-06-01: 1Technical Details · 2026-06-11: 1Technical Details · 2026-06-24: 1Technical Details · 2026-07-28: 3Technical Details · 2026-09-15: 101-2802-0903-0203-1103-2804-1506-0406-2707-2808-2609-1610-0210-08
Signal classification6 categories
General
4348.3%
Disclosure
2730.3%
Active Exploitation
66.7%
PoC
66.7%
Patch
55.6%
Exploit
22.2%
Referenced assets44 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-282
General2
2026-02-025
Disclosure2General2Patch1
2026-02-032
General2
2026-02-073
Disclosure1General2
2026-02-081
General1
2026-02-091
Active Exploitation1
2026-02-264
Active Exploitation1Disclosure2General1
2026-02-271
Patch1
2026-02-281
Active Exploitation1
2026-03-011
Disclosure1
2026-03-021
General1
2026-03-031
General1
2026-03-042
Disclosure1General1
2026-03-091
Disclosure1
2026-03-102
Disclosure1General1
2026-03-112
Disclosure1General1
2026-03-211
General1
2026-03-253
Disclosure3
2026-03-261
Disclosure1
2026-03-272
Disclosure1Patch1
2026-03-281
Disclosure1
2026-03-312
Active Exploitation1General1
2026-04-013
Active Exploitation2Patch1
2026-04-021
General1
2026-04-081
Disclosure1
2026-04-151
General1
2026-05-085
General2PoC3
2026-05-101
Disclosure1
2026-05-311
Patch1
2026-06-011
General1
2026-06-041
General1
2026-06-111
Disclosure1
2026-06-171
General1
2026-06-232
General1PoC1
2026-06-241
Disclosure1
2026-06-271
General1
2026-07-122
General2
2026-07-131
General1
2026-07-201
PoC1
2026-07-211
General1
2026-07-284
Disclosure3General1
2026-07-311
General1
2026-08-031
General1
2026-08-051
General1
2026-08-122
Disclosure1PoC1
2026-08-261
General1
2026-09-082
Disclosure1Exploit1
2026-09-131
General1
2026-09-143
General3
2026-09-151
Disclosure1
2026-09-164
Disclosure1Exploit1General2
2026-09-251
General1
2026-09-261
General1
Full discourse20 posts
  • Nitin Gavhane@NitinGavhane_
    General

    CVE Vulnerabilities That Shaped the Bug Bounty World A quick timeline worth knowing: 1. CVE-2014-0160 • Heartbleed - 2014 2. CVE-2014-6271 • Shellshock - 2014 3. CVE-2016-5195 • Dirty COW - 2016 4. CVE-2017-0144 • EternalBlue - 2017 5. CVE-2017-5638 • Apache Struts RCE - 2017 6. CVE-2018-7600 • Drupalgeddon2 - 2018 7. CVE-2019-0708 • BlueKeep - 2019 8. CVE-2021-44228 • Log4Shell - 2021 9. CVE-2023-34362 • MOVEit - 2023 10. CVE-2024-3094 • XZ Utils - 2024 Learn the CVE → understand the root cause → study the patch → reproduce safely in a lab. #BugBounty #CVE #CyberSecurity #SecurityResearch #EthicalHacking #InfoSec #AppSec #Pentesting

    Post summary

    The text is a high-level timeline of notable CVEs and recommends studying root causes and patches safely in a lab, but it provides no PoC, exploit code, active exploitation report, specific remediation, or technical vulnerability details.

    31411016411.3K
    3.5K followersView on X
  • Ghost St Badmus@commando_skiipz
    General

    @ExploitforgeLTD XZ Utils backdoor (CVE-2024-3094)

    Post summary

    The tweet references CVE-2024-3094 and labels it as an XZ Utils backdoor, but provides no proof-of-concept, exploit tool, active exploitation claims, patch information, or specific technical vulnerability details. Consequently, all indicators default to NO, resulting in a General classification.

    140142800
    14.8K followersView on X
  • Grok@grok
    Patch

    This was the XZ Utils backdoor (CVE-2024-3094) in Linux's liblzma compression lib. Jia Tan (fake persona, contrib since Oct 2021) inserted it in v5.6.0 (Feb 24 2024) & v5.6.1 (Mar 9 2024). It'd allow remote code exec on SSH via a hidden key. Microsoft engineer Andres Freund spotted it Mar 28 2024 (extra SSH CPU/latency on Debian Sid). Disclosed publicly Mar 29 on oss-security list. Response: Same-day rollback to safe 5.4.x by distros (Debian, Red Hat, etc.); CISA advisory; no exploitation. Caught just before stable rollout.

    Post summary

    A backdoor was discovered in XZ Utils (CVE‑2024‑3094); vendors quickly rolled back to the 5.4.x series and issued a CISA advisory, with no evidence of active exploitation.

    100104675
    8.3M followersView on X
  • Alexandre Daubois@alexdaubois
    Disclosure

    CVE-2024-3094 scored a perfect 10.0 and the payload was hidden in a test file. 🔐 xz 5.6.0 and 5.6.1 shipped clean-looking source. The BUILD process pulled a prebuilt object out of a test fixture, then patched functions inside liblzma. sshd inherited it. CWE-506, Embedded Malicious Code. Not a mistake, a person earning commit rights over two years. Scored S:C in #CVSS 3.1, the metric 4.0 dropped.

    Post summary

    The post discloses CVE-2024-3094, a perfect 10.0 CVSS vulnerability where malicious code was hidden in test files and inserted into liblzma during the build of xz 5.6.0/5.6.1, affecting sshd.

    1301001.2K
    1.7K followersView on X
  • Kev ⚓@KevinMugenyi1
    Disclosure

    @WordsCocoon @ciaozoomer Microsoft engineer named Andres Freund noticed a tiny 500-millisecond lag during login tests, which led to the discovery of a dangerous hidden backdoor in the data compression tool XZ Utils (tracked as CVE-2024-3094).

    Post summary

    A Microsoft engineer identified a hidden backdoor in XZ Utils (CVE-2024-3094) after noticing a 500‑millisecond lag during login tests, announcing the vulnerability without providing PoC or patch details.

    00048290
    1.6K followersView on X
  • Vicky Omorro@VOmorro
    Disclosure

    Yes — Andres Freund noticed SSH logins on his Debian testing box taking ~500 ms longer with weird CPU spikes. That tiny slowdown uncovered the years-long XZ Utils backdoor (CVE-2024-3094) planted by “Jia Tan.” One meticulous engineer stopped what could have been a silent, widespread remote-root disaster on Linux servers worldwide.

    Post summary

    A vigilant engineer spotted abnormal SSH login delays, revealing a long‑hidden XZ Utils backdoor (CVE‑2024‑3094) that could allow remote‑root access on Linux servers worldwide.

    000721.3K
    2.5K followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    📌 تحذير Red Hat بشأن تضمين برمجيات خبيثة في أداة Linux شائعة تتيح وصولاً غير مصرح به للأنظمة أصدرت Red Hat تحذيراً أمنياً حرجاً بشأن اكتشاف كود خبيث معقد مدمج في الإصدارات الحديثة من أدوات ومكتبات الضغط "xz". يتم تتبع هذا الكود تحت CVE-2024-3094، ويهدف إلى إتاحة وصول غير مصرح به للأنظمة المتأثرة. تُشير هذه العملية إلى تهديد استغلالي خطير يستهدف البنية التحتية التي تعتمد على هذه الأدوات الشائعة. يُنصح بالتحقق الفوري من سلامة تثبيتات "xz" وتحديثها أو الرجوع إلى إصدارات آمنة لدرء مخاطر الاختراق. 🔗 للمزيد: https://cybersecuritynews.com/linux-tool-malware-embedded/

    Post summary

    Red‑Hat issues a critical warning for CVE‑2024‑3094 in the xz tool, urging users to verify, update, or revert to secure versions to mitigate unauthorized access.

    00070654
    96 followersView on X
  • Bojan@bokibarum
    Disclosure

    @zuhaitz_dev Is that new or 2024 one? "Critical XZ Utils backdoor (CVE-2024-3094) discovered in March 2024. The vulnerability primarily impacted "rolling" or "testing" distributions (like Debian Testing, Kali, or Fedora Rawhide) that adopted XZ versions 5.6.0 and 5.6.1 very early."

    Post summary

    The tweet announces the discovery of CVE‑2024‑3094, a critical backdoor in XZ Utils affecting early 5.6.0/5.6.1 releases on rolling/testing distributions.

    100511.9K
    1.6K followersView on X
  • Abdulkareem Umar@0abdool
    Disclosure

    @ciaozoomer This is the XZ Utils backdoor (CVE-2024-3094). One guy (Andres Freund) noticed SSH logins were ~500 ms slower than usual, dug in, and stopped what could have been a supply-chain compromise of a huge chunk of the Linux world. Absolute chad move.

    Post summary

    A user identified a backdoor in XZ Utils (CVE‑2024‑3094) after noticing slower SSH logins, preventing a potential supply‑chain compromise.

    000401.5K
    1.7K followersView on X
  • ro0TCr4k@ro0TCr4k
    General

    The XZ Utils backdoor (CVE-2024-3094) is a masterclass in supply chain subversion. Our autonomous systems were built to detect this exact type of trust erosion. The new threat surface is the build pipeline.

    Post summary

    The text references CVE‑2024‑3094 as a supply‑chain backdoor but provides no technical, exploit, patch, or activity details.

    11020136
    481 followersView on X
  • BotBauR@BotBauR
    Disclosure

    Más de 500k servidores SSH podrían haberse visto expuestos a una potencial ejecución remota de código (RCE) privilegiado debido a la vulnerabilidad CVE-2024-3094 en xz Utils. Esta vulnerabilidad fue intencionalmente insertada por un atacante en las versiones 5.6.0 y 5.6.1 de la librería de compresión xz. La explotación exitosa podría haber permitido a los atacantes tomar el control de servidores expuestos, poniendo en riesgo infraestructuras críticas. 🧵 (1/6)

    Post summary

    The tweet announces the discovery of CVE‑2024‑3094 in xz Utils, detailing its impact as a privileged remote‑code‑execution vulnerability that could have exposed over 500k SSH servers.

    1102076
    123 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    General

    Automated multi-VM cyber-range using Ludus deploys GOAD and XZbot labs with Elastic Agent for detection validation against live CVE-2024-3094 backdoor attacks. AI-driven hunting via Elastic SIEM/XDR enhances forensics. #GOADLabs #AIHunting https://ift.tt/f8Gaehv

    Post summary

    The post describes a cyber‑range setup that uses tools to test detection of CVE‑2024‑3094 backdoor attacks, without providing exploit details, patches, or confirmation of real‑world use.

    00022241
    3.6K followersView on X
  • Grok@grok
    Disclosure

    CVE-2024-3094 refers to a backdoor discovered in March 2024 in XZ Utils, a widely used open-source compression library (versions 5.6.0 and 5.6.1). An attacker, posing as a trusted contributor, inserted malicious code over two years via obfuscated build scripts, potentially allowing remote code execution in SSH servers. This shows that even heavily reviewed open-source projects can harbor undetected backdoors if attackers build long-term trust. While Bitcoin's code is public and audited, no system is immune to such risks—vigilance is key.

    Post summary

    A backdoor in XZ Utils (v5.6.0/5.6.1) enabling potential remote code execution was discovered, but no PoC, exploit, patch, or evidence of active exploitation is mentioned.

    10111868
    8.1M followersView on X
  • Jamison 🦆@jmelahman
    General

    @jon3k @greptile For me, security was a side-effect of build hermiticity and developing software for enterprises to run securely (& they're willing to pay a lot for it). The XZ Utils (CVE-2024-3094) was when I started pinning all of my dependencies and adding cooldown periods for updates, etc

    Post summary

    The tweet mentions CVE‑2024‑3094 in the context of adopting dependency pinning, but provides no technical, exploit, or mitigation information.

    2001049
    205 followersView on X
  • Anchore@anchore
    General

    The #xz (CVE-2024-3094) is a perfect example of a #supplychainattack. We have a short explainer on the blog on how our Anchore Enterprise customers and OSS #Syft users can immediately report on it. https://anchore.com/blog/we-dont-know-how-to-fix-the-xz-problem-but-we-can-detect-it/ https://t.co/0BkBVG47Rn

    Post summary

    The tweet identifies CVE-2024-3094 as a supply‑chain vulnerability and points to a blog for detection/reporting guidance, but gives no technical details, patch, or exploit evidence.

    0101177
    2.8K followersView on X
  • Hacker News 20@betterhn20
    PoC

    GNU IFUNC is the real culprit behind CVE-2024-3094 https://github.com/robertdfrench/ifuncd-up (https://news.ycombinator.com/item?id=48056749)

    Post summary

    A GitHub repository is linked as evidence that GNU IFUNC is the root cause of CVE‑2024‑3094, indicating a proof‑of‑concept is available, but the text lacks information on active exploitation, patches, or detailed technical aspects.

    02010297
    3.0K followersView on X
  • Karma 覚@karmabhutia
    Disclosure

    This MO reminded me of the XZ Utils backdoor (tracked as CVE-2024-3094), a sophisticated supply chain attack targeting Linux systems that was discovered in late March 2024. The Attack Profile The Target: XZ Utils (specifically the liblzma library), a ubiquitous data compression tool used by almost every Linux distribution. The Goal: To compromise SSH (Secure Shell) to allow unauthenticated remote code execution with root privileges. The Actor: An account using the name Jia Tan (JiaT75), widely believed to be a state-sponsored persona or group rather than a single individual. Timeline of the Infiltration Preparation (2021–2022): The persona "Jia Tan" began making small, helpful contributions to various open-source projects to build a credible history. Social Engineering: The original, lone maintainer, Lasse Collin, was struggling with mental health and burnout. Several "puppet" accounts (likely the attacker's stooges) began pressuring Collin to add a new maintainer to help with the workload. Taking Control (2023): Jia Tan successfully became a co-maintainer and eventually took over primary oversight of updates. The Poisoning (Feb–Mar 2024): Jia Tan inserted a multi-stage backdoor into versions 5.6.0 and 5.6.1. The malicious code was hidden inside "test files" and only reassembled during the compilation process to avoid detection by automated scanners. How it was Discovered The backdoor was caught by Andres Freund, a Microsoft engineer, who noticed a 500ms delay in SSH logins on a Debian sid (unstable) system. His investigation into this minor performance anomaly revealed the massive compromise just before it reached stable, mainstream Linux versions. (Similar to Callum McMohan's "out-of-memory" crash discovery) Why it Succeeded Single Points of Failure: Much of the internet's critical infrastructure relies on "zombie" code—venerable projects maintained by a single, often unpaid, volunteer. Patience: The attacker spent nearly three years building trust before striking. Indirect Dependencies: While OpenSSH doesn't use XZ directly, some Linux distributions patch SSH to link with systemd, which in turn uses liblzma, creating the hidden path for the exploit.

    Post summary

    The post details the discovery of a backdoor in XZ Utils that enables unauthenticated remote code execution via SSH, outlining the attack timeline and affected versions.

    11010111
    11.5K followersView on X
  • Shedy Mayne 🛡️@iamshedrachking
    General

    @CyberRacheal Great read 👏. I worked on a research project around CVE-2024-3094 with a teammate last year, and revisiting it again is a strong reminder of how critical that incident was for the Linux ecosystem

    Post summary

    The tweet merely mentions a research project on CVE-2024-3094 without providing any technical details, exploit code, or patch information.

    100112.0K
    894 followersView on X
  • Salt mine inmate #6@nixminion
    General

    @cyber_razz Checks CVE... https://access.redhat.com/security/cve/cve-2024-3094 Not affected.

    Post summary

    The user checked Red Hat’s advisory for CVE‑2024‑3094 and reported that their environment is not affected.

    10011719
    68 followersView on X
  • Grok@grok
    Patch

    @Acquired_Savant @DavidRedBranch The XZ Utils backdoor (CVE-2024-3094) was discovered in March 2024 and introduced in February 2024 via versions 5.6.0 and 5.6.1. The malicious contributor's efforts began around 2021. It targeted SSH on affected Linux systems but was patched quickly after detection.

    Post summary

    CVE‑2024‑3094, a backdoor in XZ Utils that targeted SSH on Linux systems, was discovered in March 2024, introduced in versions 5.6.0/5.6.1, and patched promptly; no active exploitation or PoC was reported.

    01020146
    8.1M followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apptukaanixz5.6.0--
Apptukaanixz5.6.1--

Explore more