CVE-2024-3094 is a critical supply chain vulnerability affecting xz versions 5.6.0 and 5.6.1, where malicious code was embedded into the liblzma library. This sophisticated backdoor, disguised within test files, modifies specific functions to intercept and alter data interactions. With a CVSS score of 10.0 and an EPSS score indicating extremely high exploitability, this vulnerability allows unauthenticated remote attackers to achieve full system compromise (confidentiality, integrity, and availability). While not yet listed in CISA's KEV catalog, its high FAUCET Risk Score of 100/100, numerous community discussions, and extensive media coverage highlight its severe threat and widespread concern. Although no Metasploit or ExploitDB modules exist, Nuclei templates are available, and public repositories demonstrate reproduction of the exploit.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.6.0CPE matchmatch criteria | cpe:2.3:a:tukaani:xz:5.6.0:*:*:*:*:*:*:* | ||
5.6.1CPE matchmatch criteria | cpe:2.3:a:tukaani:xz:5.6.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Regenerate snakeoil SSH certificates and keypairs shipped in Debian-based containers
Nov 19, 2025XZ Utils backdoor – TeamViewer services are not affected
Apr 10, 2024Red Hat Enterprise Linux (RHEL) Malicious Injection Vulnerability
Apr 2, 2024Red Hat Enterprise Linux (RHEL) Malicious Injection Vulnerability
Apr 2, 2024Red Hat Enterprise Linux (RHEL) Malicious Injection Vulnerability
Apr 2, 2024Red Hat Enterprise Linux (RHEL) Malicious Injection Vulnerability
Apr 2, 2024Red Hat Enterprise Linux (RHEL) Malicious Injection Vulnerability
Apr 2, 2024Red Hat Enterprise Linux (RHEL) Malicious Injection Vulnerability
Apr 2, 2024Red Hat Enterprise Linux (RHEL) Malicious Injection Vulnerability
Apr 2, 2024Red Hat Enterprise Linux (RHEL) Malicious Injection Vulnerability
Apr 2, 2024xz: malicious code in distributed source
Mar 29, 2024