On Friday, March 29, 2024, Andres Freund, an engineer at Microsoft, identified a backdoor in the XZ Utils software. This backdoor was published by the National Vulnerability Database the same day under the reference CVE-2024-3094. The malicious code was discovered by chance during a series of tests run on a server using an infected version: Andres noticed a CPU load spike in the liblzma library, which is used by XZ Utils.
What is XZ Utils?
XZ Utils, formerly known as LZMA Utils, is a compression tool that generally outperforms GZIP or BZip2. XZ is widely used by Linux distributions.
XZ Utils consists of xz, a compression and decompression tool, and liblzma, a library that can be loaded by other tools to work with the lzma format.
What is the CVE-2024-3094 vulnerability?
CVE-2024-3094 is a critical vulnerability that allows an attacker to execute remote commands on an affected machine.
This vulnerability is a backdoor, meaning it is a piece of malicious code introduced into the XZ Utils source code by developers intending to carry out a cyberattack. This type of vulnerability falls under the category of supply chain attacks, as CVE-2024-3094 was inserted into the XZ Utils project code through open-source development processes.
In other words, CVE-2024-3094 involves the intentional insertion of malicious code into the XZ Utils project by attackers.
Fortunately, the vulnerability was detected quickly, before the malicious code could reach production in most Linux distributions.
This CVE is critical, with a 10/10 score according to Red Hat.
How does CVE-2024-3094 work?
CVE-2024-3094 relies on the fact that Debian, SUSE, Fedora, and Kali Linux use systemd notifications when handling incoming SSH connections, and that systemd uses liblzma.
Any connection attempt to the SSH service of a vulnerable server is slightly slower (about 500ms) due to the execution of the backdoor code.
According to Filippo Valsorda, known for his work on the Heartbleed vulnerability:
- The malicious code only truly activates if the attacker connects to SSH with an OpenSSH certificate specifically crafted to exploit CVE-2024-3094;
- The malicious code deactivates when an OpenSSH certificate authentication occurs and the process does not lead to an attack.
The malicious code's ability to deactivate in the event of an unsuccessful attack makes it difficult to detect this vulnerability via network scans, as well as difficult for random attackers to use.
How can CVE-2024-3094 in XZ Utils be exploited?
Exploiting CVE-2024-3094 requires preparing a malicious OpenSSH certificate with specific cryptographic properties.
Based on the information currently available, it appears that only the team behind the insertion of the backdoor into the XZ Utils code can effectively exploit this vulnerability.
How did the attacker insert the backdoor code into XZ Utils?
The attack took place over several years via the GitHub account JiaT75 (Jia Tan). Thomas Roccia, an engineer at Microsoft, produced a detailed diagram tracing the timeline of the attack, which was widely shared by the security community following its discovery.
CVE-2024-3094: which systems are affected by this vulnerability?
The malicious code behind CVE-2024-3094 was detected before it reached production on most major Linux distributions on the market.
Consequently, development branches such as Debian SID or Alpine Linux Edge are the main versions impacted.
The vulnerable systems are:
- Debian SID / Debian Unstable / Debian 13 (development version): xz-utils versions lower than 5.6.1+really5.4.5-1 (source).
- Alpine Linux Edge : xz-utils versions lower than 5.6.1-r2 (source).
- ArchLinux : xz versions 5.6.0-1 and 5.6.1-1; the vulnerability has been fixed in version 5.6.1-2 (source).
- Fedora 40 Linux beta / Fedora Rawhide : xz-libs versions 5.6.0-1 and 5.6.0-2; no patch is available for Fedora 40 Linux beta, Red Hat recommends reverting to xz-libs 5.4.X; Fedora 40 Linux is not affected (source).
Distributions not mentioned in this list are, according to publicly available information, not impacted by this vulnerability.
I am using a system affected by CVE-2024-3094, what should I do?
Cyberwatch recommends applying the security patches provided by your distribution as soon as possible.
Additionally, Cyberwatch recommends checking SSHD logs to monitor all incoming connections, and even system logs to check for the loading of the liblzma library during an incoming SSH connection.
For affected systems, it is best to assume the system has been compromised and to perform a full reinstallation if necessary.
It should also be noted that development distributions such as Fedora Rawhide or Debian SID are not recommended for standard production environments.
How to detect CVE-2024-3094?
Check if you are using one of the XZ Utils versions mentioned earlier in this article.
Users of the vulnerability management platform Cyberwatch can already detect this vulnerability as of March 29, 2024. Please feel free to contact our team for any information requests.
Change log
03/31/2024 at 2:39 PM GMT+2: initial version
