#liblzma
*clears throat*

liblzma balls
March 29, 2024 at 7:20 PM
Woah. Backdoor in liblzma targeting ssh servers.

www.openwall.com/lists/oss-se...

It has everything: malicious upstream, masterful obfuscation, detection due to performance degradation, inclusion in OpenSSH via distro patches for systemd support…

Now I’m curious what it does in RSA_public_decrypt
oss-security - backdoor in upstream xz/liblzma leading to ssh server compromise
www.openwall.com
March 29, 2024 at 4:49 PM
"backdoor in upstream xz/liblzma leading to ssh server compromise" seclists.org/oss-sec/2024...
oss-sec: backdoor in upstream xz/liblzma leading to ssh server compromise
seclists.org
March 29, 2024 at 6:07 PM
liblzma and xz version 5.6.0 and 5.6.1 are vulnerable to arbitrary code execution compromise

xeiaso.net/notes/2024/x...
liblzma and xz version 5.6.0 and 5.6.1 are vulnerable to arbitrary code execution compromise - Xe Iaso
xeiaso.net
March 29, 2024 at 5:38 PM
Près d'un an après la divulgation de l'incroyable backdoor qui avait frappé le projet xz-utils, ce dernier vient de publier une version 5.8.0, avec de grandes améliorations de performances, des corrections et améliorations diverses ⬇️

github.com/tukaani-proj...
Release XZ Utils 5.8.0 (stable) · tukaani-project/xz
5.8.0 (2025-03-25) This bumps the minor version of liblzma because new features were added. The API and ABI are still backward compatible with liblzma 5.6.x, 5.4.x, 5.2.x, and 5.0.x. ...
github.com
March 27, 2025 at 6:56 AM
Une backdoor a été découverte dans la liblzma. On est en train de raccrocher tous les wagons et c'est 🤯
cc @lealinux.bsky.social
March 29, 2024 at 8:04 PM
i was staring at the liblzma backdoor a bit and put some notes up. nothing thrilling, but maybe useful references for others: www.iximeow.net/xz.html
March 29, 2024 at 11:33 PM
broski 5 years ago this would have taken me 2 years to fix and made me grow as a person and as a developer to fix
July 24, 2026 at 12:39 AM
Recent ssh (xz/liblzma) backdoor was scary but very predictable. I haven't trusted exposing OpenSSH to the world for 15+ years.

Been laughing imaging the very sad state agency hacker tasked with trying to create a remote backdoor in WireGuard that bypasses its pre-shared key check, etc. Good luck!
April 8, 2024 at 5:53 PM
$ xz --version
xz (XZ Utils) 5.6.1
liblzma 5.6.1
💀
March 30, 2024 at 9:08 AM
I've hit the "sunk cost fallacy" phase of waiting for liblzma to source build. Is something wrong with my depgraph? Probably. Am I going to stop and fix it? No.
November 7, 2025 at 10:32 PM
just taking a large sip of hot coffee on my first day as liblzma community manager and infosec evangelist, and checking out seclists dot org,
March 29, 2024 at 6:16 PM
Happy xz CVE-2024-3094 day to all who celebrate.

news.ycombinator.com/item?id=3986...
Backdoor in upstream xz/liblzma leading to SSH server compromise | Hacker News
news.ycombinator.com
March 31, 2024 at 2:59 PM
xzユーティリティの上流バージョン(5.6.0)にバックドアが仕掛けられていたとな
www.openwall.com/lists/oss-se...
oss-security - backdoor in upstream xz/liblzma leading to ssh server compromise
www.openwall.com
March 29, 2024 at 7:01 PM
Bonjour et bon dimanche ! Le projet xz-utils, qui avait défrayé la chronique il y a deux mois, est disponible en version 5.6.2, version totalement libérée de la fameuse backdoor qui avait été ajoutée par Jia Tan dans la liblzma ⬇️

github.com/tukaani-proj...
GitHub - tukaani-project/xz: XZ Utils
XZ Utils. Contribute to tukaani-project/xz development by creating an account on GitHub.
github.com
June 2, 2024 at 6:28 AM
i know the computer does not care about my opinions on its impudence but making liblzma resolve and hook RSA functions if they happen to be in the address space is really an impressive level of gall
March 29, 2024 at 7:23 PM
liblzma tarballs
March 31, 2024 at 6:17 AM
xz 5.6.0と5.6.1にバックドアがあるらしい
www.openwall.com/lists/oss-se...
oss-security - backdoor in upstream xz/liblzma leading to ssh server compromise
www.openwall.com
March 30, 2024 at 3:28 AM
ALERT: liblzma and xz version version 5.6.0 and 5.6.1 have backdoors installed into their code. Downgrade below 5.6.0 or upgrade to 5.6.2 when it is released. More to come when I learn more.
March 29, 2024 at 5:02 PM
Xz/liblzma: Bash-stage Obfuscation Explained Discussion
xz/liblzma: Bash-stage Obfuscation Explained
gynvael.coldwind.pl
March 30, 2024 at 10:40 PM
liblzma does that?!
March 29, 2024 at 7:25 PM
i haven't found (and tbh haven't yet tried to find) an affected liblzma, do you have one on hand?
March 29, 2024 at 8:04 PM
Link roundup related to xz/liblzma compromise (CVE-2024-3094) shellsharks.com/xz-compromis...
xz/liblzma Compromise Link Roundup
Links to analysis, discussion and more related to the xz/liblzma compromise (CVE-2024-3094)
shellsharks.com
March 31, 2024 at 4:51 PM
Am Wochenende war was los: xz/liblzma und ssh, Linux und Postgres, es geht um Hintertüren und Angriffe auf Lieferketten, da sind die Open Source Community, Hans Jansen und Jia Tan — was wild klingt, hat mein DNIP.ch-Kollege Marcel Waldvogel sortiert: dnip.ch/2024/04/02/x...
April 2, 2024 at 7:33 AM