Skip to main content

XZ Utils reveals open source supply chain risk

Malicious code was discovered in versions 5.6.0 and 5.6.1 of XZ Utils, a widespread utility in Linux systems.

CybersecuritySeintec team2-3 min read
XZ Utils reveals open source supply chain risk

News summary

Malicious code was discovered in versions 5.6.0 and 5.6.1 of XZ Utils, a widespread utility in Linux systems. The issue, CVE-2024-3094, could interfere with SSH authentication under specific conditions and triggered rapid rollback measures across Linux distributions.

A company also relies on components it may never have directly contracted. Inventorying libraries, versions, images, and dependencies allows for a swift response to a supply chain vulnerability.

Source: CERT-EU — 30 March 2024

What happened

On 29 March 2024 engineer Andres Freund noticed unusual SSH behaviour while investigating a performance issue and uncovered a backdoor in versions 5.6.0 and 5.6.1 of the XZ Utils compression library. The malicious code had been introduced gradually by a contributor who had spent a long time earning the project's trust.

The affected versions had mainly reached development or testing distributions such as Fedora Rawhide and Debian unstable, and were pulled within hours.

Why it matters to any business

Most organisations don't know which XZ Utils version they run, or even that they use it. That is exactly the supply-chain risk: dependencies nobody bought, sitting in servers, network devices and containers.

The case also shows the value of disciplined updating: production environments on stable releases were not affected.

What to review

Practices that let you respond in hours rather than weeks:

  • An inventory of operating systems, versions and packages on every server.
  • Separate test and production environments, with stable releases in production.
  • A software bill of materials (SBOM) for in-house and vendor applications.
  • Monitoring of security advisories from the distributions and vendors you use.

Frequently Asked Questions

Was every Linux server affected?
No. Only those running versions 5.6.0 or 5.6.1, found mainly in development distributions.
What is a supply-chain attack?
One that compromises a third-party component to reach its users, instead of attacking the victim directly.
How do we check our exposure?
By checking the installed version of the xz package on each system against the affected versions.

Concepts mentioned in this article: Vulnerability

Every company has different risks and needs. At Seintec, we can analyse your infrastructure and propose a tailored solution, without oversizing or complicating your environment. Contact us.

Contact Seintec

Related service

Cybersecurity

We shield your business so it never stops.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.