CVE-2024-3094

CVSS v3.1 10 (Critical)
100% Progress
EPSS 12.90 % (96th)
12.90% Progress
Affected Products 1
Advisories 3
NVD Status Modified

Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0.
Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.

Weaknesses
CWE-506
Embedded Malicious Code
CVE Status
PUBLISHED
NVD Status
Modified
CNA
Red Hat, Inc.
Published Date
2024-03-29 17:15:21
(8 months ago)
Updated Date
2024-11-21 09:28:53
(3 weeks ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Tukaani Xz 5.6.0 cpe:2.3:a:tukaani:xz:5.6.0
  Tukaani Xz 5.6.1 cpe:2.3:a:tukaani:xz:5.6.1
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...