CVE-2024-3094
xz Utils supply-chain backdoor
Malicious code in the upstream xz 5.6.0 and 5.6.1 tarballs. The backdoor shipped in the release artifacts. It is not in the CISA KEV catalog as of 5 October 2026.
- CVSS
- 10
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Class
- Supply chain
- Status
- Exploit Available
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- xz project
- Products
- xz, liblzma
- Affected
- xz 5.6.0 and 5.6.1 upstream tarballs.
- Fixed
- Downgrade to 5.4.6, the release widely recommended after disclosure. Do not treat a later 5.6 build as safe without checking the project advisory.
- CWE
- CWE-506
- Published
- 29 Mar 2024
- Updated
- 5 Oct 2026
The status above is the claim. Links do not upgrade it.
CVE-2024-3094 is malicious code planted in the upstream tarballs of xz, starting with 5.6.0. During the build, a disguised test file yielded a prebuilt object that modified functions in liblzma. Software linked against that library could be exposed to the backdoor.
NVD scores it 10.0 under CWE-506, embedded malicious code. The status on this record is Exploit Available because the malicious build itself was published in the 5.6.0 and 5.6.1 tarballs. That is not the same as a separate, weaponized exploit kit, and it is not a claim of widespread confirmed exploitation. Discovery became public on 29 March 2024, before the backdoor had clearly propagated through stable distributions.
Checked against the CISA KEV catalog on 5 October 2026, CVE-2024-3094 was not listed. The 0-day flag stays off: this was a supply-chain implant, recorded here as a compromised release rather than as pre-patch exploitation of a vendor product.
The practical fix published at the time was to revert to 5.4.6. Follow the oss-security thread and the distribution advisories before choosing any later build. This page does not include the backdoor payload or a reproduction.