{
    "id": "CVE-2024-3094",
    "published": "2024-03-29 17:15:21",
    "last_modified": "2026-06-17 07:43:17",
    "cvss_score": "10.0",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
    "cwe": "CWE-506",
    "description": "Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. \r\nThrough a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.",
    "epss_score": "0.85974",
    "epss_percentile": "0.99724",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 0,
    "updated_at": "2026-09-26 18:48:51",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "EPSS 86% — above the 10% action threshold."
    },
    "products": [
        {
            "vendor": "tukaani",
            "product": "xz"
        }
    ],
    "kev_detail": null,
    "exploits": [],
    "refs_list": [
        "https://access.redhat.com/security/cve/CVE-2024-3094",
        "https://bugzilla.redhat.com/show_bug.cgi?id=2272210",
        "https://www.openwall.com/lists/oss-security/2024/03/29/4",
        "https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users",
        "http://www.openwall.com/lists/oss-security/2024/03/29/10",
        "http://www.openwall.com/lists/oss-security/2024/03/29/12",
        "http://www.openwall.com/lists/oss-security/2024/03/29/4",
        "http://www.openwall.com/lists/oss-security/2024/03/29/5",
        "http://www.openwall.com/lists/oss-security/2024/03/29/8",
        "http://www.openwall.com/lists/oss-security/2024/03/30/12",
        "http://www.openwall.com/lists/oss-security/2024/03/30/27",
        "http://www.openwall.com/lists/oss-security/2024/03/30/36",
        "http://www.openwall.com/lists/oss-security/2024/03/30/5",
        "http://www.openwall.com/lists/oss-security/2024/04/16/5",
        "https://access.redhat.com/security/cve/CVE-2024-3094",
        "https://ariadne.space/2024/04/02/the-xz-utils-backdoor-is-a-symptom-of-a-larger-problem/",
        "https://arstechnica.com/security/2024/03/backdoor-found-in-widely-used-linux-utility-breaks-encrypted-ssh-connections/",
        "https://aws.amazon.com/security/security-bulletins/AWS-2024-002/",
        "https://blog.netbsd.org/tnf/entry/statement_on_backdoor_in_xz",
        "https://boehs.org/node/everything-i-know-about-the-xz-backdoor",
        "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024",
        "https://bugs.gentoo.org/928134",
        "https://bugzilla.redhat.com/show_bug.cgi?id=2272210",
        "https://bugzilla.suse.com/show_bug.cgi?id=1222124",
        "https://discourse.nixos.org/t/cve-2024-3094-malicious-code-in-xz-5-6-0-and-5-6-1-tarballs/42405"
    ]
}