Case C87989 · Famous breaches · L4 Advanced
xz-utils backdoor
Practise as: Explain it · Deep dive
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- CVE-2024-3094: backdoor in xz/liblzma 5.6.0 and 5.6.1, found by Andres Freund on 29 March 2024
- 'Jia Tan' spent about 2 years earning maintainer trust, aided by sock-puppet pressure on the original maintainer
- Payload hid in test files and release tarballs, not visible git source, via a modified build-to-host.m4
- sshd loaded liblzma through distro libsystemd patches; an IFUNC hook hijacked RSA_public_decrypt for key-gated RCE
- Caught early from ~500 ms SSH latency; shipped in rolling/pre-release distros (Debian sid, Fedora 40/Rawhide, Tumbleweed, Kali, Arch)
If the interviewer pushes back
- What reproducible-build or tarball-vs-git checks would have caught this, and who is responsible for running them?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.