XZ Utils CVE-2024-3094: A Tale of Broken Trust, Curious Persistence, and a Call to Action
hackerone.com | vulnerability | CVE-2024-3094 | #supply-chain | #open-source | #linux | #backdoor | #xz-utils | #cve-2024-3094
Summary
A backdoor in XZ Utils 5.6.0 and 5.6.1 (CVE-2024-3094) surfaced when Andres Freund noticed sshd slowdowns; the code hid in compressed test files after a long-grooming supply chain effort.
- Published
- Collected
Skip to content