216.73.216.233

CVE-2024-3094

· Published 29/03/2024 18:15 · Modified 21/12/2025 03:42 · Author: The MITRE Corporation

Labels: CVE-2024-3094

Essential information

Published
29/03/2024 18:15
Modified
21/12/2025 03:42
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
10.0 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/C:H/I:H/A:H

CVSS metrics

Description

Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.

NVD status

NVD
View on NVD