Urgent: Secret Backdoor Found in XZ Utils Library, Impacts Major Linux Distros
Two versions of the well-known data compression library XZ Utils (formerly LZMA Utils) have been backdoored with malicious code intended to grant unauthorized remote access, according to a "urgent security alert" issued by Red Hat on Friday.
The software supply chain compromise, identified by the tracking number CVE-2024-3094, has a maximum severity of 10.0 on the CVSS scale. It affects XZ Utils 5.6.1 (published on March 9) and 5.6.0 (issued on February 24).
The liblzma build process uses a number of intricate obfuscations to extract a prebuilt object file from a covert test file that is present in the source code. This object file is then used to change particular functions within the liblzma code," the IBM subsidiary stated in an advisory.
As a result, the liblzma library is al...

