Listen

Description

xz-utils Backdoor CVE-2024-3094

https://www.openwall.com/lists/oss-security/2024/03/29/4

https://tukaani.org/xz-backdoor/

https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27

Backdoor reverse analysis

https://bsky.app/profile/did:plc:x2nsupeeo52oznrmplwapppl/post/3kowjkx2njy2b

YARA Rule

https://github.com/byinarie/CVE-2024-3094-info/blob/main/CVE-2024-3094.yar

Social Engineering Attempts to Include Backdoor in Distros

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067708

https://news.ycombinator.com/item?id=39866275

Github Repo (now disabled)

https://github.com/tukaani-project/xz

Statements from Distributions

https://www.kali.org/blog/about-the-xz-backdoor/

https://archlinux.org/news/the-xz-package-has-been-backdoored/

https://access.redhat.com/security/cve/CVE-2024-3094

https://bugs.gentoo.org/928134

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024