xz-utils backdoor: CVE-2024-3094 urgent advisory
A malicious backdoor discovered in xz 5.6.0/5.6.1 can allow unauthorized access over SSH.
A malicious backdoor discovered in xz 5.6.0/5.6.1 can allow unauthorized access over SSH.
xz-utils package versions 5.6.0 and 5.6.1 contain malicious code that can hook into the OpenSSH process and create a remote unauthorized access backdoor. One of the most severe supply chain incidents on record.
Stable Ubuntu releases are not affected; however, Noble beta/preview images contained the risky xz version. Canonical rapidly released clean packages.
xz --version → If 5.6.0 or 5.6.1, urgent intervention is requiredThe kernel update released for Ubuntu 24.04 LTS addresses a use-after-free vulnerability in the nf_tables component.
A signal handler race condition in the OpenSSH server carries a risk of unauthenticated RCE as root.
Bulk security patches for the OpenSSL, curl, sudo and systemd packages were published this month.