CVE-2024-3094 PoC 探索 https://github.com/amlweems/xzbot
https://tukaani.org/xz-backdoor/ - Lasse Collin 的回应
https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27
https://www.reddit.com/r/linux/comments/1brhlur/xz_utils_backdoor/
https://gist.github.com/smx-smx/a6112d54777845d389bd7126d6e9f504
CVE-2024-3094 的相关信息
Red Hat 今天针对 Fedora 41 和 Fedora Rawhide 用户发布了关于 XZ 的“紧急安全警报”。没错,就是这种压缩格式的 XZ 工具和库。XZ 5.6.0/5.6.1 中被添加了某些恶意代码,可能允许未经授权的远程系统访问。
Red Hat 因恶意代码进入代码库而将此 XZ 安全漏洞标记为 CVE-2024-3094。我还没有看到 CVE-2024-3094 公开披露,但 Red Hat 安全警报将其总结为: “xz 5.6.0 和 5.6.1 库中存在的恶意注入代码经过混淆处理,且仅在下载包中完整包含——Git 发行版缺少触发恶意代码构建的 M4 宏。如果恶意 M4 宏存在,Git 仓库中的第二阶段工件会在构建时被注入。
由此产生的恶意构建会通过 systemd 干扰 sshd 中的身份验证。SSH 是远程连接系统的常用协议,而 sshd 是提供访问权限的服务。在适当的情况下,这种干扰可能使恶意行为者绕过 sshd 身份验证,并远程获得对整个系统的未经授权访问。”
后门逆向分析
在发行版中植入后门的社会工程尝试
GitHub 仓库(现已禁用)
各发行版的声明
https://www.mail-archive.com/[email protected]/msg00571.html
https://linuxsecurity.com/advisories/debian/debian-dsa-5649-1-xz-utils-security-update-miwy4lbzklq4
https://lists.debian.org/debian-security-announce/2024/msg00057.html
https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users
https://www.reddit.com/r/linux/comments/1bqt999/backdoor_in_upstream_xzliblzma_leading_to_ssh/
https://www.reddit.com/r/sysadmin/comments/1bqu3zx/backdoor_in_upstream_xzliblzma_leading_to_ssh/
https://linuxsecurity.com/advisories/debian/debian-dsa-5649-1-xz-utils-security-update-miwy4lbzklq4