Critical SEVERITY — Vulnerability

xz-utils backdoor: CVE-2024-3094 urgent advisory

A malicious backdoor discovered in xz 5.6.0/5.6.1 can allow unauthorized access over SSH.

Platform
Ubuntu Server
Version
24.04 LTS / Noble Numbat
CVE Record
CVE-2024-3094
CVSS Score
10.0/10
Published
29 March 2024
Views
4
Primary source: Review the official advisory at ubuntu.com Kaynağa Git

Summary

xz-utils package versions 5.6.0 and 5.6.1 contain malicious code that can hook into the OpenSSH process and create a remote unauthorized access backdoor. One of the most severe supply chain incidents on record.

Ubuntu Status

Stable Ubuntu releases are not affected; however, Noble beta/preview images contained the risky xz version. Canonical rapidly released clean packages.

Checks

  • xz --version → If 5.6.0 or 5.6.1, urgent intervention is required
  • Suspect systems must be reinstalled from the image
xz-utils liblzma5

Ubuntu Server — Related Advisories

VIEW ALL →