bk99.de entertain the web since 1997

The XZ backdoor: Half a second of suspicion

Summary

Andres Freund traces unusual SSH latency and high CPU load to a cleverly hidden backdoor in XZ and liblzma versions 5.6.0 and 5.6.1. Andres Freund published the warning on oss-security on 29 March 2024. The affected releases were the upstream XZ versions 5.6.0 and 5.6.1.

Ideas

  • Small performance deviations can be the first visible sign of a compromise.
  • Manipulated release archives can contain different code from the publicly reviewed repository.
  • Inconspicuous test files and build scripts can assemble a payload together.
  • Transitive library dependencies carry attacks unexpectedly into security-critical services.
  • Long-term social influence can bypass a project’s technical safeguards.
  • Multi-stage activation conditions make analysis harder and limit accidental discovery.

Insights

  • Observability is also a security control, because attacks rarely work entirely without traces.
  • Open source only protects if the published source code and the shipped artefacts verifiably match.
  • Understaffed key projects turn human overload into a systemic supply chain risk.

Quotes

  • After observing a few odd symptoms around liblzma I figured out the answer. – Andres Freund

Habits

  • Freund kept investigating unusual runtime, CPU load and analysis tools, although at first there was no established security incident.

Facts

  • The complete backdoor was not simply present as readable code in the Git repository.
  • Activation targeted certain x86-64 Linux builds with glibc and DEB or RPM tooling.

References

Critique

  • The first report was a hasty technical situation report and not yet a complete postmortem.
  • The backdoor only worked under certain build and runtime conditions, not on every XZ system.

Remarks

  • The investigation started with about half a second of additional SSH latency.
  • The case shows technical manipulation and targeted social influence as a combined attack.

Recommendations

  • Compare published archives reproducibly with the corresponding repository states.
  • Alert on unexplained latency and CPU deviations in security-critical services.
  • Fund and relieve maintainers of critical, widely used libraries.

Read the original report

Search the Web Archive