# CVE-2024-3094: XZ Utils backdoor enables remote code execution via SSH

DevFeed: [CVE-2024-3094: XZ Utils backdoor enables remote code execution via SSH](<https://devfeed.tech/articles/backdoor-in-xz-utils-allows-rce-everything-you-need-to-know-53755.md>)

Original publisher: [Read original article](<https://www.wiz.io/blog/cve-2024-3094-critical-rce-vulnerability-found-in-xz-utils>)

Author: Danielle Aminov

Published: 2024-03-29T22:02:58Z

Content type: article

Language: en

Sources: [Wiz](<https://devfeed.tech/sources/wiz-blog-rss-feed.md>)

Topics: [CVE 2024 3094](<https://devfeed.tech/topics/cve-2024-3094.md>), [xz](<https://devfeed.tech/topics/xz.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Library](<https://devfeed.tech/topics/library.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [Compression](<https://devfeed.tech/topics/compression.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [cve-2024-3094](<https://devfeed.tech/tags/cve-2024-3094.md>), [linux](<https://devfeed.tech/tags/linux.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [rce](<https://devfeed.tech/tags/rce.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [xz](<https://devfeed.tech/tags/xz.md>)

## AI overview

This article explains CVE-2024-3094, a supply-chain backdoor in XZ Utils that can enable remote code execution through SSH under specific conditions. It describes the affected build process, potentially vulnerable Linux distributions, cloud exposure, and recommended mitigation.

## Source excerpt

Detect and mitigate CVE-2024-3094, a critical supply chain compromise, affecting XZ Utils Data compression library. Organizations should patch urgently.