All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

Malicious Backdoor Discovered in XZ Utils Compression Software Affecting Linux Systems

By

ctrlmeta

5mo ago· 14 min readenNews

Summary

The article details the discovery of a sophisticated backdoor in the XZ Utils compression software, a critical open-source component used in Linux distributions. The backdoor was introduced in versions 5.6.0 and 5.6.1 by an account named 'Jia Tan' and allowed attackers with a specific Ed448 private key to execute arbitrary code on affected systems. The vulnerability was discovered by Andres Freund in March 2024 and quickly patched, but it raised significant concerns about supply chain security in open-source software and the potential for state-sponsored attacks on critical infrastructure.

Key quotes

· 4 pulled
In February 2024, a malicious backdoor was introduced to the Linux build of the xz utility within the liblzma library in versions 5.6.0 and 5.6.1 by an account using the name 'Jia Tan'.
The backdoor gives an attacker who possesses a specific Ed448 private key remote code execution capabilities on affected systems.
The vulnerability was discovered by Andres Freund in March 2024 and represents one of the most sophisticated supply chain attacks on open-source software.
This incident highlights critical vulnerabilities in the open-source software supply chain and the potential for state-sponsored attacks on critical infrastructure.
Snippet from the RSS feed
Previous XZ logo contributed by Jia Tan

You might also wanna read