ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Supply chain attack targets major Linux distributions with backdoored XZ Utils library

A supply chain attack has targeted major Linux distributions, introducing backdoored versions of the XZ Utils data compression library. Discovered by Microsoft software engineer Andres Freund, the malicious code was embedded in XZ Utils version 5.6.0, released in February 2024, and further refined in version 5.6.1.

 

The backdoor, tracked by Red Hat as CVE-2024-3094, allows unauthenticated access to the system by modifying the liblzma library. Through obfuscated techniques, the code interferes with authentication in sshd via systemd, potentially granting attackers unauthorized access to systems.

 

Affected distributions include Fedora Rawhide, Fedora Linux 40 beta, openSUSE Tumbleweed, openSUSE MicroOS, Kali Linux, and Arch Linux. Debian and Ubuntu have confirmed that no stable releases are impacted, while Amazon Linux, Alpine Linux, Gentoo Linux, and Linux Mint remain unaffected.

 

Security researchers have developed a script to scan systems for the malicious library, as XZ Utils is widely used not only in Linux distributions but also as a dependency for other libraries, posing significant implications.

The backdoor, introduced by XZ Utils maintainer Jia Tan, utilizes a multi-stage loader and a function for deploying updates via additional files to conceal its presence. Tan, whose GitHub account has been suspended, modified the library to include the malicious code in early 2024.

 

While Tan only had access to the GitHub repository, not to the project’s website or Git repositories, the attackers didn’t need to commit the code publicly. Modifying the release of tarball hosted on GitHub was sufficient, making the tarball changes less suspicious.

 

To mitigate the threat, users are advised to downgrade XZ Utils to version 5.4.x, with 5.4.6 being the latest stable, uncompromised iteration. The US cybersecurity agency CISA recommends developers and users take immediate action to address the vulnerability and monitor systems for any malicious activity.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543