The XZ Utils Backdoor
Updated 5 Oct 2026 · Incident date 24 Feb 2024 · source tarball
xz-utils 5.4.6 -> 5.6.0 (and 5.6.1)m4/build-to-host.m4XZ Utils versions 5.6.0 and 5.6.1 contain a backdoor, tracked as CVE-2024-3094. Version 5.4.6 is the safe version to use. Andres Freund disclosed the backdoor on 29 March 2024 on the Openwall oss-security list.
The release tarballs held a build file that unpacked and ran hidden code while the software compiled. The code targeted SSH on some Linux systems.
What happened
Andres Freund found the backdoor and reported it on Openwall. He saw that logins over SSH were slower than normal. The compromise came through a contributor named Jia Tan, who had gained commit access over about two years, according to the FAQ by Sam James.
There are two injection points. The first is a script in the file m4/build-to-host.m4, which exists only in the release tarballs. It runs at the configure stage. The second is two test files in the repository, tests/files/bad-3-corrupt_lzma2.xz and tests/files/good-large_compressed.lzma. The build script decodes the hidden program from these files and runs it.
The hidden code hooks the ifunc resolvers in liblzma and redirects RSA_public_decrypt(). OpenSSH does not use liblzma. But many distributions patch OpenSSH to use libsystemd, and libsystemd depends on liblzma. So a patched sshd loads the bad library.
The code activates only under narrow conditions:
- x86-64 Linux with glibc
- GCC with the GNU linker
- A Debian or RPM package build
- At runtime, the process is
/usr/sbin/sshd, withTERMunset andLANGset, and no debugger
Affected versions
XZ Utils and liblzma 5.6.0 and 5.6.1 are affected. Snyk reports that 5.6.0 came out on 24 February 2024 and 5.6.1 on 9 March 2024.
- Bad: 5.6.0 and 5.6.1
- Good: 5.4.6 and earlier
Snyk lists these distributions as having shipped the bad versions: Debian testing and unstable, Fedora Rawhide and Fedora 40, Kali Linux and openSUSE Tumbleweed. Most stable releases used older XZ versions and were not affected.
Indicators of compromise
m4/build-to-host.m4in a tarball with the serial number changed from 3 to 30 (Snyk)- The files
tests/files/bad-3-corrupt_lzma2.xzandtests/files/good-large_compressed.lzma, added in commitscf44e4b7and74b138d2and reverted ine93e13c8 - Slower SSH logins on a system that runs a bad liblzma
- A liblzma version string of 5.6.0 or 5.6.1
How to check
Check the installed xz version.
xz --version
A result of 5.6.0 or 5.6.1 means you must act. On Debian and Ubuntu, also check the package.
dpkg -l | grep -E "xz-utils|liblzma"
On Fedora and other RPM systems, run rpm -q xz xz-libs. To check source trees, search for the changed build file.
grep -rl "build-to-host" . --include=*.m4
What to do now
- Downgrade to xz 5.4.6 or apply the patched package from your distribution.
- Restart sshd after you update liblzma.
- Treat a system that ran a bad version with a reachable SSH port as possibly compromised, and review it.
- Rebuild any container image or package that you built with the bad tarball.
- Compare release tarballs with the tagged source. This attack lived in files that the repository did not have.
Vigilance compares the version you trust with a new one. It reports a build file that decodes a payload and runs it. See all attacks.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 21 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED m4/build-to-host.m4 It now downloads from the internet. It did not before.
Frequently asked questions
Which XZ Utils versions have the backdoor?
Versions 5.6.0 and 5.6.1. Version 5.4.6 is the safe version. The CVE is CVE-2024-3094.
How do I check if I have the XZ backdoor?
Run xz --version. A result of 5.6.0 or 5.6.1 means the system has an affected version. Downgrade to 5.4.6 or install your distribution's patched package.
Sources
More supply chain attacks
- Webmin SourceForge build backdoor 1 Apr 2018
- phpMyAdmin 3.5.2.2 SourceForge mirror backdoor 22 Sept 2012
- vsftpd 2.3.4 backdoor 30 Jun 2011
- ProFTPD 1.3.3c source tarball backdoor 28 Nov 2010
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.