GeistHaus
log in · sign up

xz-utils backdoor situation (CVE-2024-3094)

gist.github.com

xz-utils backdoor situation (CVE-2024-3094). GitHub Gist: instantly share code, notes, and snippets.

22 pages link to this URL
xz/liblzma Backdoor: Open Source Nuke? Maybe Not That Bad!

xz/liblzma Backdoor: Open Source Nuke? Maybe Not That Bad! Story Background On March 29, 2024, a report exposing a backdoor in the upstream source code of the controversial open-source project, the xz software package, was made public on the oss-security mailing list.

1 inbound link website en open source securityCyber BunkerHardenedVaultLinux kernel threatLinux kernel mitigationfirmware securitytrusted computing
CVE-2024-3094: Malicious code in xz 5.6.0 and 5.6.1 tarballs

There is currently an ongoing discussion on various platforms about a security issue in xz/liblzma, and here is what we know at this time. This post serves as a way to inform the community about our assessment of the impact on nixpkgs. Summary It was discovered that xz from version 5.6.0 started shipping malicious code that would only be executed through its release tarballs. A malicious code path would be executed when running configure and modify the resulting liblzma library. Impact NixOS 2...

3 inbound links website en
Friday Links 24-10

Heisenberg’s indeterminacy principle formula. Two weeks of links, which includes a collection from the xz debacle. I loved reading these, as this is a good combination of spy story and technology postmortem. If you want to read an overview, read the timeline post. Good podcasts this week: about the Heisenberg principle, and the silencing of climate protesters in the UK. Leadership Getting real with Employee Experience [Podcast] - two good interviews with people active in the area.

0 inbound links article en post environmenturbanismfriday linksleadershipengineeringfridaylinks
xz/liblzma Compromise Link Roundup

Links to analysis, discussion and more related to the xz/liblzma compromise (CVE-2024-3094).

2 inbound links article en infosec xz/liblzma Compromise Link Roundupshellsharksinfosecsupplychain
xz backdoor - Dmitry Kudryavtsev

A malicious backdoor was discovered in xz library that implements LZMA compression. xz, among many other places, is used, indirectly, in sshd. My attempt to explain what happened.

1 inbound link article en Security CC BY-NC 4.0
SE Radio 630: Luis Rodríguez on the SSH Backdoor Attack
0 inbound links en agileaiapiarchitecturec#cloudcompilersconcurrencydatabasedatabasesdesigndevopsdistributed systemsDockerdomain-driven designgarbage collectionIEEE Computer SocietyieeecsinfrastructureInterviewjavaJavaScriptkuberneteslanguagesmachine learningmicroservicesmonitoringnetworkingopen sourcepatternsperformancepodcastprocessesprogramming languagespythonrubyRustscalabilitySE-RadiosecuritySE RadioSQLTechnology/GuestTechnology Talktesting
The xz backdoor from a Security Engineer persepective

As you probably already heard, the xz package got compromised. The package was used as entrypoint to inject malicious code in sshd, altering the authentication flow. This forged vulnerability is now known as CVE-2024-3094.

1 inbound link article en posts backdoorCVE-2024-3094xzliblzmasupply-chainsecurity-engineering