
CS50 Cybersecurity Final Project - Analysis of CVE-2024-3094
An in-depth technical and architectural breakdown of CVE-2024-3094 (CVSS 10.0 Critical), the historic open-source supply chain backdoor embedded into xz-utils / liblzma (versions 5.6.0 and 5.6.1) discovered in March 2024.
This presentation was developed as the Final Project for CS50’s Introduction to Cybersecurity by Harvard University / edX.
In March 2024, a critical supply chain attack was discovered inside xz-utils, a fundamental compression utility utilized across major Linux distributions (Debian, Fedora, Ubuntu, Arch, RHEL). Assigned the maximum vulnerability score of CVSS 10.0, the backdoor targeted liblzma.so during compilation to hijack OpenSSH (sshd) processes, allowing unauthorized remote code execution (RCE) with full root privileges.
This project examines the complete lifecycle of the vulnerability across five key dimensions:
liblzma and core system security concepts.m4 execution, and GNU IFUNC symbol hijacking.bad-3-corrupt_lzma2.xz). An injected build-to-host.m4 macro verified environment conditions (x86_64 Linux target packaging) before extracting and linking the payload during binary generation.liblzma. The backdoor utilized GNU Indirect Functions (IFUNC) to hook into memory during dynamic symbol resolving, replacing RSA_public_decrypt.syslog), while non-matching attempts passed through seamlessly to standard authentication..
├── presentation_slides/ # High-resolution 16:9 presentation slides (PNG)
│ ├── slide1_title.png
│ ├── slide2_social_engineering.png
│ ├── slide3_technical_details.png
│ ├── slide4_discovery.png
│ └── slide5_mitigation.png
├── audio_transcripts/ # AI Voiceover transcripts and timing scripts
│ └── narration_script.txt
├── README.md # Project documentation and summary
└── project_details.txt # Course submission metadata