Toutes les vulnérabilités
CRITICALSupply chainexploited in the wild

CVE-2024-3094

Linux/Open Source · xz-utils / liblzma

Résumé

Disclosed March 29, 2024, CVE-2024-3094 is a backdoor planted over a multi-year social-engineering campaign by a maintainer persona known as 'Jia Tan' (JiaT75), who gained trust and commit rights to the XZ Utils compression project. Malicious code hidden in the release tarballs of versions 5.6.0 and 5.6.1 hooked into liblzma and, when linked by sshd via systemd, allowed an attacker holding a specific Ed448 private key to bypass SSH authentication and achieve remote code execution. It scored CVSS 10.0 and was caught by Microsoft engineer Andres Freund noticing a 500ms SSH login delay before it reached most stable distributions.

Références

Vulnérabilités liées

Tout Supply chain →