Wind River Support Network

HomeDefectsLIN1021-7932
Fixed

LIN1021-7932 : Security Advisory - xz - CVE-2024-3094

Created: Mar 30, 2024    Updated: Apr 3, 2024
Resolved Date: Apr 2, 2024
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.



CREATE(Triage):(User=admin) CVE-2024-3094 (https://nvd.nist.gov/vuln/detail/CVE-2024-3094)
Live chat
Online