Open cardosec

Case C87989 · Famous breaches · L4 Advanced

xz-utils backdoor

Practise as: Explain it · Deep dive
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. CVE-2024-3094: backdoor in xz/liblzma 5.6.0 and 5.6.1, found by Andres Freund on 29 March 2024
  2. 'Jia Tan' spent about 2 years earning maintainer trust, aided by sock-puppet pressure on the original maintainer
  3. Payload hid in test files and release tarballs, not visible git source, via a modified build-to-host.m4
  4. sshd loaded liblzma through distro libsystemd patches; an IFUNC hook hijacked RSA_public_decrypt for key-gated RCE
  5. Caught early from ~500 ms SSH latency; shipped in rolling/pre-release distros (Debian sid, Fedora 40/Rawhide, Tumbleweed, Kali, Arch)

If the interviewer pushes back

  • What reproducible-build or tarball-vs-git checks would have caught this, and who is responsible for running them?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.