# Chainguard's response to CVE-2024-3094, aka the backdoor in xz library

DevFeed: [Chainguard's response to CVE-2024-3094, aka the backdoor in xz library](<https://devfeed.tech/articles/chainguard-s-response-to-cve-2024-3094-aka-the-backdoor-in-xz-library-12995.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguards-response-to-cve-2024-3094-aka-the-backdoor-in-xz-library>)

Published: 2024-03-29T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [Compression](<https://devfeed.tech/topics/compression.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [compression](<https://devfeed.tech/tags/compression.md>), [customer-trust](<https://devfeed.tech/tags/customer-trust.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2024-3094](<https://devfeed.tech/tags/cve-2024-3094.md>), [liblzma](<https://devfeed.tech/tags/liblzma.md>), [linux](<https://devfeed.tech/tags/linux.md>), [malware](<https://devfeed.tech/tags/malware.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [secure-images](<https://devfeed.tech/tags/secure-images.md>), [security](<https://devfeed.tech/tags/security.md>), [xz](<https://devfeed.tech/tags/xz.md>), [xz-library](<https://devfeed.tech/tags/xz-library.md>)

## AI overview

Chainguard describes its response to CVE-2024-3094, a backdoor introduced into the upstream xz/liblzma project. It says its Images were not affected, while impacted packages were withdrawn, revoked, and rebuilt with unaffected liblzma versions.

## Source excerpt

Chainguard effectively addresses CVE-2024-3094 in xz library, showcasing quick action to secure images and uphold customer trust.