News Feed Background Pattern
Secret Backdoor Found in XZ Utils Library, Impacts Major Linux Distros
26-October-2024
|Fusion Cyber
Featured image for article: Secret Backdoor Found in XZ Utils Library, Impacts Major Linux Distros

Urgent: Secret Backdoor Found in XZ Utils Library, Impacts Major Linux Distros

A secret backdoor has been discovered in the XZ Utils compression library, used by several major Linux distributions including Fedora, Kali Linux, and openSUSE. This has been reported by The Hacker News.

Key Details:

  • Vulnerability: CVE-2024-3094, with a CVSS score of 10.0 (maximum severity).
  • Affected Versions: XZ Utils 5.6.0 (released February 24) and 5.6.1 (released March 9).
  • Impact: Malicious code allows unauthorized remote access, potentially hijacking the system via interference with the sshd daemon and systemd. The attacker can inject code into the OpenSSH server, allowing execution of arbitrary payloads before authentication.
  • Discovery: Andres Freund, a Microsoft engineer and PostgreSQL developer, discovered and reported the issue.
  • Attribution: The malicious code was introduced via commits by a user named Jia Tan (JiaT75) to the Tukaani Project on GitHub. The repository has since been disabled by GitHub.
  • Affected Distributions: Primarily Fedora 41 and Fedora Rawhide. Distributions like Alpine Linux, Amazon Linux, Debian Stable, Gentoo Linux, Linux Mint, Red Hat Enterprise Linux (RHEL), SUSE Linux Enterprise and Leap, and Ubuntu are not impacted.
  • Recommendation: Downgrade to XZ Utils 5.4.6 (or a similarly uncompromised version) as a precaution. Fedora 40 users are advised to downgrade to a 5.4 build.

How the Backdoor Works:

The malicious code is heavily obfuscated. It involves a prebuilt object file disguised within a test file in the source code. During the liblzma build process, this object file is extracted and used to modify functions in the library, allowing interception and modification of data interactions.

Responses:

  • Red Hat: Issued an urgent security alert.
  • JFrog: Provided analysis on the backdoor's functionality.
  • GitHub: Disabled the affected XZ Utils repository.
  • CISA: Issued an alert urging users to downgrade.

Note: At the time of this report, there are no reports of active exploitation in the wild.

Background

Start Your AI & Cyber Journey Today

Gain the Skills, Certifications, and Support You Need to Secure Your Future. Enroll Now and Step into a High-Demand Career !

More News

Cyber News Feed

TOP STORIES

AI Panel On August 7th moderated by Fusion Cyber AI

|Fusion Cyber

Army Navy Country Club, 1700 Army Navy Drive, Arlington, VA

Read More
AI Panel On August 7th moderated by Fusion Cyber AI
Fusion Cyber Launches 12 AI Engineering Scholarships for JROTC Cadets, Air Force DRIVE Participants, and Faith-Based Schools

Fusion Cyber Launches 12 AI Engineering Scholarships for JROTC Cadets, Air Force DRIVE Participants, and Faith-Based Schools

Read More
Fusion Cyber AI Meeting the National AI & Cyber Workforce Mandate

Fusion Cyber AI Meeting the National AI & Cyber Workforce Mandate

Read More
From Freeway to Firewalls: FusionCyber.AI Hits the Streets of Silicon Valley

From Freeway to Firewalls: FusionCyber.AI Hits the Streets of Silicon Valley

Read More