Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.
CVE-2024-3094
Score 10.0 from GitHub Security Advisory (severity: CRITICAL) published 2024-03-29. NVD baseline CVSS 10.0; sources differ by 0.0.
- High exploitation likelihood — EPSS 86%
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 10.0
- EG Score
- 10.0(medium)
- EPSS
- 99.7%
- KEV
- Not listed
Published
March 29, 2024
Last Modified
June 17, 2026
Advisory Details (10)
Auto-updated Jul 18, 2026oss-security - Re: backdoor in upstream xz/liblzma leading to ssh server compromise
http://www.openwall.com/lists/oss-security/2024/03/30/12oss-security - Re: backdoor in upstream xz/liblzma leading to ssh server compromise
http://www.openwall.com/lists/oss-security/2024/03/29/8oss-security - Re: backdoor in upstream xz/liblzma leading to ssh server compromise
http://www.openwall.com/lists/oss-security/2024/03/29/5oss-security - backdoor in upstream xz/liblzma leading to ssh server compromise
http://www.openwall.com/lists/oss-security/2024/03/29/4oss-security - Re: backdoor in upstream xz/liblzma leading to ssh server compromise
http://www.openwall.com/lists/oss-security/2024/03/29/12oss-security - Re: backdoor in upstream xz/liblzma leading to ssh server compromise
http://www.openwall.com/lists/oss-security/2024/03/29/10Urgent security alert for Fedora 40 and Fedora Rawhide users
https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-usersoss-security - backdoor in upstream xz/liblzma leading to ssh server compromise
https://www.openwall.com/lists/oss-security/2024/03/29/42272210 – (CVE-2024-3094) CVE-2024-3094 xz: malicious code in distributed source
https://bugzilla.redhat.com/show_bug.cgi?id=2272210Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 5× in last 7d / 15× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-07-22 14:07 UTCEPSS rescore
- 2026-07-22 14:07 UTCEPSS rescore
- 2026-07-20 17:06 UTCEPSS rescore
- 2026-07-15 16:56 UTCEPSS rescore
- 2026-07-15 16:56 UTCEPSS rescore
- 2026-07-13 22:29 UTCEPSS rescore
- 2026-07-12 21:37 UTCOSV refresh
- 2026-07-12 05:45 UTCEPSS rescore
- 2026-07-06 02:22 UTCEPSS rescore
- 2026-07-06 02:22 UTCEPSS rescore
- 2026-07-01 15:05 UTCEPSS rescore
- 2026-06-25 13:49 UTCEPSS rescore
- 2026-06-24 07:20 UTCOSV refresh
- 2026-06-23 21:32 UTCEPSS rescore
- 2026-06-23 21:32 UTCEPSS rescore
- 2026-06-18 17:52 UTCEPSS rescore
- 2026-06-18 17:51 UTCEPSS rescore
- 2026-06-17 17:52 UTCEPSS rescore
- 2026-06-15 17:47 UTCEPSS rescore
- 2026-06-14 23:16 UTCEPSS rescore
- 2026-06-13 22:59 UTCEPSS rescore
- 2026-06-13 22:59 UTCEPSS rescore
- 2026-06-12 23:11 UTCEPSS rescore
- 2026-06-10 22:17 UTCEPSS rescore
- 2026-06-10 13:21 UTCEPSS rescore
Show 19 moreShow fewer
- 2026-06-08 14:16 UTCEPSS rescore
- 2026-06-07 10:59 UTCOSV refresh
- 2026-06-06 13:46 UTCEPSS rescore
- 2026-06-06 13:46 UTCEPSS rescore
- 2026-06-05 22:46 UTCEPSS rescore
- 2026-06-05 22:46 UTCEPSS rescore
- 2026-06-05 06:09 UTCEPSS rescore
- 2026-06-05 06:09 UTCEPSS rescore
- 2026-06-04 13:11 UTCEPSS rescore
- 2026-06-04 13:11 UTCEPSS rescore
- 2026-06-02 20:12 UTCEPSS rescore
- 2026-06-01 13:51 UTCEPSS rescore
- 2026-06-01 13:51 UTCEPSS rescore
- 2026-05-29 13:43 UTCEPSS rescore
- 2026-05-28 13:44 UTCEPSS rescore
- 2026-05-28 13:44 UTCEPSS rescore
- 2026-05-28 13:44 UTCEPSS rescore
- 2026-05-23 04:00 UTCEG score recompute
- 2026-05-23 04:00 UTCGHSA enrichment
Publicly available exploits
(10 references)Working exploit code is in the public domain (10 GitHub PoCs). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoCrobertdfrench/ifuncd-upFirst seen Jul 5, 2024
GNU IFUNC is the real culprit behind CVE-2024-3094
Open source ↗ - GitHub PoCamlweems/xzbot✓ verifiedFirst seen Apr 2, 2024
Reverse-engineered honeypot + reproduction harness for the xz-utils backdoor.
Open source ↗ - GitHub PoCr0binak/xzk8sFirst seen Apr 2, 2024
Dockerfile and Kubernetes manifests for reproduce CVE-2024-3094
Open source ↗ - GitHub PoC0xlane/xz-cve-2024-3094First seen Apr 1, 2024
XZ Backdoor Extract(Test on Ubuntu 23.10)
Open source ↗ - Open source ↗GitHub PoCjfrog/cve-2024-3094-toolsFirst seen Mar 31, 2024
- GitHub PoCgensecaihq/CVE-2024-3094-Vulnerability-Checker-FixerFirst seen Mar 30, 2024
Shell scripts to identify and fix installations of xz-utils affected by the CVE-2024-3094 vulnerability. Versions 5.6.0 and 5.6.1 of xz-utils are known to be vulnerable, and this script aids in detecting them and optionally downgrading to a stable, un-compromised version (5.4.6) or upgrading to latest version. Added Ansible Playbook
Open source ↗ - GitHub PoClockness-Ko/xz-vulnerable-honeypotFirst seen Mar 30, 2024
An ssh honeypot with the XZ backdoor. CVE-2024-3094
Open source ↗ - GitHub PoCteyhouse/CVE-2024-3094First seen Mar 30, 2024
K8S and Docker Vulnerability Check for CVE-2024-3094
Open source ↗ - GitHub PoCbyinarie/CVE-2024-3094-infoFirst seen Mar 29, 2024
Information for CVE-2024-3094
Open source ↗ - GitHub PoCFabioBaroni/CVE-2024-3094-checkerFirst seen Mar 29, 2024
Quick and dirty PoC for checking whether a vulnerable version of xz-utils is installed (CVE-2024-3094)
Open source ↗
Past incidents using this CVE
(1)This CVE was central to one or more publicly-documented breaches. Each card links to authoritative reporting at the time of the incident.
- xz-utils backdoorMar 2024
Multi-year social-engineering attack inserted a backdoor into xz-utils, used by sshd via systemd. Caught accidentally by a Microsoft engineer before reaching stable Debian/Ubuntu. Closest call in OSS supply-chain history.
Source: Ars Technica
Related CVEs(same CWE)
Same CWE
10 shownCWE-506
Frequently asked(5)
What is CVE-2024-3094?
When was CVE-2024-3094 disclosed?
Is CVE-2024-3094 actively exploited?
What is the CVSS score of CVE-2024-3094?
How do I remediate CVE-2024-3094?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2024-3094
Is Your Infrastructure Affected by CVE-2024-3094?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.