
Investigation into the XZ Utils backdoor (CVE-2024-3094): chronology, attack chain, risk to SSH, and supply-chain insights. Includes slides, sources, and mitigations (parity checks, attestations, or SBOMs, as well as SLSA)
Case Study: XZ Utils Backdoor (CVE-2024-3094)
This repository supports my 7-10 minute presentation on the XZ Utils backdoor, including a recap of the backdoor, the mechanism for the backdoor via release tarballs, and relevant supply-chain mitigations.
Andres Freund, these files acknowledge everyone in the distro for finding and remediating this.
Presenter: Gianluca Milani,edX: Gianluca25,GitHub: M1lo25
Recorded Date: 16/10/2025