Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2024-3094: Embedded Malicious Code

0
Critical
VulnerabilityCVE-2024-3094cvecve-2024-3094
Published: Fri Mar 29 2024 (03/29/2024, 16:51:12 UTC)
Source: CVE Database V5

Description

Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.

Technical Details

Data Version
5.2
Assigner Short Name
redhat
Date Reserved
2024-03-29T15:38:13.249Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 691ec3729f5a9374a9d10f9a

Added to database: 11/20/2025, 7:29:54 AM

Last updated: 11/20/2025, 7:30:35 AM

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.