CVE-2024-3094

CVSS v3 10 (Critical)
EPSS 14.45 % (96th)
Affected Products 1
Advisories 3

Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0.
Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.

Weaknesses
CWE-506
Embedded Malicious Code
CNA
Red Hat, Inc.
secalert@redhat.com
Published Date
2024-03-29 17:15:21
(3 months ago)
Updated Date
2024-05-01 19:15:27
(2 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Tukaani Xz 5.6.0 cpe:2.3:a:tukaani:xz:5.6.0
  Tukaani Xz 5.6.1 cpe:2.3:a:tukaani:xz:5.6.1
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...