The XZ backdoor: Half a second of suspicion
Summary
Andres Freund traces unusual SSH latency and high CPU load to a cleverly hidden backdoor in XZ and liblzma versions 5.6.0 and 5.6.1. Andres Freund published the warning on oss-security on 29 March 2024. The affected releases were the upstream XZ versions 5.6.0 and 5.6.1.
Ideas
- Small performance deviations can be the first visible sign of a compromise.
- Manipulated release archives can contain different code from the publicly reviewed repository.
- Inconspicuous test files and build scripts can assemble a payload together.
- Transitive library dependencies carry attacks unexpectedly into security-critical services.
- Long-term social influence can bypass a project’s technical safeguards.
- Multi-stage activation conditions make analysis harder and limit accidental discovery.
Insights
- Observability is also a security control, because attacks rarely work entirely without traces.
- Open source only protects if the published source code and the shipped artefacts verifiably match.
- Understaffed key projects turn human overload into a systemic supply chain risk.
Quotes
After observing a few odd symptoms around liblzma I figured out the answer.
– Andres Freund
Habits
- Freund kept investigating unusual runtime, CPU load and analysis tools, although at first there was no established security incident.
Facts
- The complete backdoor was not simply present as readable code in the Git repository.
- Activation targeted certain x86-64 Linux builds with glibc and DEB or RPM tooling.
References
- Andres Freund: backdoor in upstream xz/liblzma leading to ssh server compromise
- CVE-2024-3094: identifier of the manipulated XZ/liblzma versions.
- OpenSSH and systemd: the connection path through which liblzma got into affected processes.
Critique
- The first report was a hasty technical situation report and not yet a complete postmortem.
- The backdoor only worked under certain build and runtime conditions, not on every XZ system.
Remarks
- The investigation started with about half a second of additional SSH latency.
- The case shows technical manipulation and targeted social influence as a combined attack.
Recommendations
- Compare published archives reproducibly with the corresponding repository states.
- Alert on unexplained latency and CPU deviations in security-critical services.
- Fund and relieve maintainers of critical, widely used libraries.
Links to the original source and the Web Archive open in a new tab.