Skip to content
THREATWIRE

CVE

CriticalExploit Available

CVE-2024-3094

xz Utils supply-chain backdoor

Malicious code in the upstream xz 5.6.0 and 5.6.1 tarballs. The backdoor shipped in the release artifacts. It is not in the CISA KEV catalog as of 5 October 2026.

CVSS
10
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Class
Supply chain
Status
Exploit Available
KEV
Not in CISA KEV
0-day
No
Vendor
xz project
Products
xz, liblzma
Affected
xz 5.6.0 and 5.6.1 upstream tarballs.
Fixed
Downgrade to 5.4.6, the release widely recommended after disclosure. Do not treat a later 5.6 build as safe without checking the project advisory.
Published
29 Mar 2024
Updated
5 Oct 2026

The status above is the claim. Links do not upgrade it.

CVE-2024-3094 is malicious code planted in the upstream tarballs of xz, starting with 5.6.0. During the build, a disguised test file yielded a prebuilt object that modified functions in liblzma. Software linked against that library could be exposed to the backdoor.

NVD scores it 10.0 under CWE-506, embedded malicious code. The status on this record is Exploit Available because the malicious build itself was published in the 5.6.0 and 5.6.1 tarballs. That is not the same as a separate, weaponized exploit kit, and it is not a claim of widespread confirmed exploitation. Discovery became public on 29 March 2024, before the backdoor had clearly propagated through stable distributions.

Checked against the CISA KEV catalog on 5 October 2026, CVE-2024-3094 was not listed. The 0-day flag stays off: this was a supply-chain implant, recorded here as a compromised release rather than as pre-patch exploitation of a vendor product.

The practical fix published at the time was to revert to 5.4.6. Follow the oss-security thread and the distribution advisories before choosing any later build. This page does not include the backdoor payload or a reproduction.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2024-3094