Backdoor found in XZ utilities used by many Linux distros (CVE-2024-3094)
by LkStr - Saturday March 30, 2024 at 12:47 PM
#1
https://www.openwall.com/lists/oss-secur...24/03/29/4

https://www.helpnetsecurity.com/2024/03/...-backdoor/

Kali Linux announced that the impact of this vulnerability affected Kali between March 26th and March 29th. If you updated your Kali installation on or after March 26th, applying the latest updates today is crucial to address this issue. However, if you did not update your Kali installation before the 26th, you are not affected by this backdoor vulnerability.
Reply
#2
(03-30-2024, 12:47 PM)LkStr Wrote: https://www.openwall.com/lists/oss-secur...24/03/29/4

https://www.helpnetsecurity.com/2024/03/...-backdoor/

Kali Linux announced that the impact of this vulnerability affected Kali between March 26th and March 29th. If you updated your Kali installation on or after March 26th, applying the latest updates today is crucial to address this issue. However, if you did not update your Kali installation before the 26th, you are not affected by this backdoor vulnerability.

It is not just Kali Linux.

Arch also updated its xz package for the same reason
Ban reason: Self-Ban (Permanent)
Reply
#3
(03-30-2024, 12:52 PM)WillyWonka Wrote:
(03-30-2024, 12:47 PM)LkStr Wrote: https://www.openwall.com/lists/oss-secur...24/03/29/4

https://www.helpnetsecurity.com/2024/03/...-backdoor/

Kali Linux announced that the impact of this vulnerability affected Kali between March 26th and March 29th. If you updated your Kali installation on or after March 26th, applying the latest updates today is crucial to address this issue. However, if you did not update your Kali installation before the 26th, you are not affected by this backdoor vulnerability.

It is not just Kali Linux.

Arch also updated its xz package for the same reason

Arch wasn't affected, the build script was configured to only inject the malicious code in Debian/Fedora based package build environments.
Ban reason: Requested. (Permanent)
Reply
#4
(06-06-2024, 12:45 PM)cuck Wrote:
(03-30-2024, 12:52 PM)WillyWonka Wrote:
(03-30-2024, 12:47 PM)LkStr Wrote: https://www.openwall.com/lists/oss-secur...24/03/29/4

https://www.helpnetsecurity.com/2024/03/...-backdoor/

Kali Linux announced that the impact of this vulnerability affected Kali between March 26th and March 29th. If you updated your Kali installation on or after March 26th, applying the latest updates today is crucial to address this issue. However, if you did not update your Kali installation before the 26th, you are not affected by this backdoor vulnerability.

It is not just Kali Linux.

Arch also updated its xz package for the same reason

Arch wasn't affected, the build script was configured to only inject the malicious code in Debian/Fedora based package build environments.

Yes, the malicious code path did not exist in the arch version of sshd by default.

However, there was a vulnerable package.

https://security.archlinux.org/AVG-2851
Ban reason: Self-Ban (Permanent)
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  CVE-2025-40554 - SolarWinds Web Help Desk Auth Bypass & RCE PoC miyako 3 79 02-07-2026, 03:32 PM
Last Post: cysc
  POC CVE-2025-24071 caca28sapo1 15 810 02-07-2026, 08:53 AM
Last Post: hacker0123
  HPE OneView RCE Exploit [CVE-2025-37164] Hawx01 8 266 02-06-2026, 07:08 PM
Last Post: hacker0123
  CitrixBleed / CVE-2023-4966 cccp 10 6,807 02-06-2026, 01:36 AM
Last Post: temptest
  WordPress LFI to RCE - CVE-2025-0366 Serious 1 463 02-05-2026, 09:53 AM
Last Post: Sammm89



 Users browsing this thread: 1 Guest(s)