XZ Utils reveals open source supply chain risk
Malicious code was discovered in versions 5.6.0 and 5.6.1 of XZ Utils, a widespread utility in Linux systems.

News summary
Malicious code was discovered in versions 5.6.0 and 5.6.1 of XZ Utils, a widespread utility in Linux systems. The issue, CVE-2024-3094, could interfere with SSH authentication under specific conditions and triggered rapid rollback measures across Linux distributions.
A company also relies on components it may never have directly contracted. Inventorying libraries, versions, images, and dependencies allows for a swift response to a supply chain vulnerability.
Source: CERT-EU — 30 March 2024
What happened
On 29 March 2024 engineer Andres Freund noticed unusual SSH behaviour while investigating a performance issue and uncovered a backdoor in versions 5.6.0 and 5.6.1 of the XZ Utils compression library. The malicious code had been introduced gradually by a contributor who had spent a long time earning the project's trust.
The affected versions had mainly reached development or testing distributions such as Fedora Rawhide and Debian unstable, and were pulled within hours.
Why it matters to any business
Most organisations don't know which XZ Utils version they run, or even that they use it. That is exactly the supply-chain risk: dependencies nobody bought, sitting in servers, network devices and containers.
The case also shows the value of disciplined updating: production environments on stable releases were not affected.
What to review
Practices that let you respond in hours rather than weeks:
- An inventory of operating systems, versions and packages on every server.
- Separate test and production environments, with stable releases in production.
- A software bill of materials (SBOM) for in-house and vendor applications.
- Monitoring of security advisories from the distributions and vendors you use.
Frequently Asked Questions
- Was every Linux server affected?
- No. Only those running versions 5.6.0 or 5.6.1, found mainly in development distributions.
- What is a supply-chain attack?
- One that compromises a third-party component to reach its users, instead of attacking the victim directly.
- How do we check our exposure?
- By checking the installed version of the xz package on each system against the affected versions.
Concepts mentioned in this article: Vulnerability
Every company has different risks and needs. At Seintec, we can analyse your infrastructure and propose a tailored solution, without oversizing or complicating your environment. Contact us.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.