Feed/CVE-2024-3094
CVE-2024-3094CRITICALCVSS 10.0

CVE-2024-3094

Published Mar 29, 2024·Updated Jun 17, 2026

NVD Description

Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.

Public Exploits & PoCs74 found

PoC: xzbot

notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094)

329

PoC: CVE-2024-3094-Vulnerability-Checker-Fixer

This project contains a shell script designed to help users identify and fix installations of xz-utils affected by the CVE-2024-3094 vulnerability. Versions 5.6.0 and 5.6.1 of xz-utils are known to be vulnerable, and this script aids in detecting them and optionally downgrading to a stable, un-compromised version (5.4.6).

5

PoC: CVE-2024-3094

K8S and Docker Vulnerability Check for CVE-2024-3094

3

PoC: CVE-2024-3094-Vulnerabity-Checker

Verify that your XZ Utils version is not vulnerable to CVE-2024-3094

3

PoC: cve-2024-3094

A tutorial on how to detect the CVE 2024-3094

2

PoC: xzk8s

Dockerfile and Kubernetes manifests for reproduce CVE-2024-3094

2

PoC: CVE-2024-3094-XZ-Utils-Check

Herramientas de linux para diferentes funciones.

2

PoC: CVE-2024-3094

Just a script to test if xz is vulnerable to the cve 2024-3094.

1

PoC: xzwhy

XZ Utils CVE-2024-3094 POC for Kubernetes

1

PoC: xz-backdoor-CVE-2024-3094-Check

Verify if your installed version of xz-utils is vulnerable to CVE-2024-3094 backdoor

1

PoC: CVE-2024-3094

Detectar CVE-2024-3094

1

PoC: CVE-2024-3094

Checker - CVE-2024-3094

1

PoC: CVE-2024-3094

Obsidian notes about CVE-2024-3094

1

PoC: CVE-2024-3094-EXPLOIT

xz exploit to privilege escalation in Linux

1

PoC: xz-backdoor-github

History of commits related to the xz backdoor Discovered On March 29, 2024: CVE-2024-3094.

1

PoC: cs50-cybersecurity-final-project

CS50 Cybersecurity Final Project: Technical Analysis of the XZ Utils Backdoor (CVE-2024-3094)

PoC: cs50-cybersecurity-final-project

CS50 Cybersecurity Final Project - Analysis of CVE-2024-3094

PoC: Report-XZ-Utils-CVE-2024-3094

Hello,

PoC: xz

Vendored xz-utils @ 5.8.3 (post-CVE-2024-3094) — portable binary distribution for x-cmd, musl-static + macOS + Windows MSYS

PoC: Semantic-Backdoor-Detector

GNN-based supply chain backdoor detector for Python packages. Uses Code Property Graphs + 3-layer GCN to detect obfuscated backdoors by learning semantic data flow patterns — not just signatures. Inspired by XZ Utils (CVE-2024-3094).

PoC: xz-backdoor-research

CVE-2024-3094 XZ Utils backdoor research - attack surface visualiser, system vulnerability checker, and general Linux CVE assessment tool

PoC: lab_xz_backdoor

Some labs looking at the xz backdoor vulnerability (CVE-2024-3094)

PoC: CVE-2024-3094

CVE-2024-3094

PoC: CVE-2024-3094

CVE-2024-3094 - XZ Utils Backdoor

PoC: sec_review_cve-2024-3094

Security review уязвимости CVE-2024-3094 с открытым исходным кодом

PoC: CVE-2024-3094

Research of CVE-2024-3094 vulnerability.

PoC: CVE-2024-3094

CVE-2024-3094

PoC: xz-cve-2024-3094

Python demo simulating CVE-2024-3094: a supply chain backdoor in XZ Utils with a trigger-based stealth activation.

PoC: Blackash-CVE-2024-3094

CVE-2024-3094

PoC: xzutils_backdoor_obfuscation

Script to obfuscate a payload the same way as it was done by the XZ utils attack (CVE-2024-3094)

PoC: CS50FinalProject

Investigation into the XZ Utils backdoor (CVE-2024-3094): chronology, attack chain, risk to SSH, and supply-chain insights. Includes slides, sources, and mitigations (parity checks, attestations, or SBOMs, as well as SLSA)

PoC: CS50Cybersecurity

Investigation into the XZ Utils backdoor (CVE-2024-3094): chronology, attack chain, risk to SSH, and supply-chain insights. Includes slides, sources, and mitigations (parity checks, attestations, or SBOMs, as well as SLSA).

PoC: -CVE-2024-3094-Vulnerability-Checker-Fixer-Public

A lightweight utility designed to detect and remediate systems affected by CVE-2024-3094, a critical vulnerability impacting [insert affected software/library here if known]. This tool provides automated scanning, reporting, and optional mitigation steps to help administrators and security teams secure their environments quickly.

PoC: CVE-2024-3094

CVE-2024-3094 exposed a backdoor in the XZ compression library, allowing remote SSH access by bypassing authentication. It’s a major supply chain attack affecting Linux systems, highlighting risks in trusted open-source components.

PoC: CVE-2024-3094-analysis

Security analysis project: Real-world CVE breakdown

PoC: TryHack

CVE-2024-3094

PoC: threat-intel-cve-2024-3094

Threat intelligence report analyzing the xz-utils backdoor vulnerability (CVE-2024-3094)

PoC: cve-2024-3094

A XZ backdoor vulnerability explained in details

PoC: Linux---Security---Detect-and-Mitigate-CVE-2024-3094

It was determined that malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. # It was determined that only certain operating systems and operating system versions were affected by this vulnerability.

PoC: CVE-2024-3094

CVE-2024-3094 실습 환경 구축 및 보고

PoC: cve-2024-3094-xz-backdoor-exploit

CVE-2024-3094 (XZ Backdoor) Tools

PoC: ifuncd-up

GNU IFUNC is the real culprit behind CVE-2024-3094

PoC: CVE-2024-3094

SSH EXPLOIT BYPASS AUTH SSH

PoC: CVE-2024-3094

Basic POC to test CVE-2024-3094 vulnerability inside K8s cluster

PoC: CVE-2024-3094

Basic POC to test CVE-2024-3094

PoC: Sicurezza-Informatica-Presentazione

Presentazione per il corsi di sicurezza Informatica sulla vulnerabilità CVE-2024-3094

PoC: Detectar-Backdoor-en-liblzma-de-XZ-utils-CVE-2024-3094-

La siguiente regla YARA ayuda a detectar la presencia del backdoor en la librería liblzma comprometida en sistemas que utilizan las versiones 5.6.0 y 5.6.1 de la herramienta de compresión XZ.

PoC: xz-backdoor-scan

Scan for files containing the signature from the `xz` backdoor (CVE-2024-3094)

PoC: ludus_xz_backdoor

An Ansible Role that installs the xz backdoor (CVE-2024-3094) on a Debian host and optionally installs the xzbot tool.

PoC: ansible-playbook-cve-2024-3094

A small repo with a single playbook.

PoC: ansible-CVE-2024-3094

An Ansible playbook to check and remediate CVE-2024-3094 (XZ Backdoor)

PoC: liblzma-scan

Scans liblzma from xu-utils for backdoor (CVE-2024-3094)

PoC: CVE-2024-3094-Checker

The CVE-2024-3094 Checker is a Bash tool for identifying if Linux systems are at risk from the CVE-2024-3094 flaw in XZ/LZMA utilities. It checks XZ versions, SSHD's LZMA linkage, and scans for specific byte patterns, delivering results in a concise table format.

PoC: CVE-2024-3094-Checker

The repository consists of a checker file that confirms if your xz version and xz-utils package is vulnerable to CVE-2024-3094.

PoC: CVE-2024-3094-backdoor-env-container

This is a container environment running CVE-2024-3094 sshd backdoor instance, working with https://github.com/amlweems/xzbot project. IT IS NOT Docker, just implemented by chroot.

PoC: CVE-2024-3094-fix-exploits

Collection of Detection, Fix, and exploit for CVE-2024-3094

PoC: CVE-2024-3094

Our current information about the CVE-2024-3094 backdoor.

PoC: xz-backdoor-links

apocalypxze: xz backdoor (2024) AKA CVE-2024-3094 related links

PoC: CVE-2024-3094

CVE-2024-3094 - Checker (fix for arch etc)

PoC: CVE-2024-3094-XZ-Backdoor-Detector

CVE-2024-3094 XZ Backdoor Detector

PoC: revisaxzutils

Script en bash para revisar si tienes la vulnerabilidad CVE-2024-3094.

PoC: xz-cve-2024-3094

XZ Backdoor Extract

PoC: CVE-2024-3094

Obsidian notes about CVE-2024-3094

PoC: xz-backdoor-vulnerability

CVE-2024-3094

PoC: XZ-Utils_CVE-2024-3094

XZ-Utils工具库恶意后门植入漏洞(CVE-2024-3094)

PoC: CVE-2024-3094-patcher

Ansible playbook for patching CVE-2024-3094

PoC: CVE-2024-3094

A script to detect if xz is vulnerable - CVE-2024-3094

PoC: CVE-2024-3094

CVE-2024-3094

PoC: xz-vulnerable-honeypot

An ssh honeypot with the XZ backdoor. CVE-2024-3094

PoC: xz-utils-vuln-checker

Checker for CVE-2024-3094 where malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code.

PoC: CVE-2024-3094_xz_check

This repository contains a Bash script and a one-liner command to verify if a system is running a vulnerable version of the "xz" utility, as specified by CVE-2024-3094.

PoC: xz_cve-2024-3094_detection

Script to detect CVE-2024-3094.

PoC: CVE-2024-3094-checker

Quick and dirty PoC for checking whether a vulnerable version of xz-utils is installed (CVE-2024-3094)

PoC: CVE-2024-3094-info

Information for CVE-2024-3094

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free