A backdoor has been found in the xz code of versions 5.6.0 and 5.6.1

Debian developer and information security researcher Andres Freund reports the discovery of a probable backdoor in the source code of xz versions 5.6.0 and 5.6.1.

The backdoor is a line in one of the m4 scripts, which appends obfuscated malicious code to the end of the configure script. This code subsequently modifies one of the generated Makefiles of the project, ultimately leading to the injection of malicious code (disguised as a test archive bad-3-corrupt_lzma2.xz) into the liblzma binary.

A distinctive feature of the incident is that the malicious code is contained only in the distributed tar archives with the source code and is not present in the project's git repository.

It is reported that the individual whose name was used to add the malicious code to the project repository is either directly involved in the incident or has fallen victim to a serious compromise of their personal accounts (but the researcher leans towards the former, as this person participated personally in several discussions related to the malicious changes).

In the link, the researcher notes that ultimately the aim of the backdoor appears to be injecting code into the sshd process and substituting the RSA key verification code, providing several indirect ways to check whether the malicious code is currently executing on your system.

According to a news article from the openSUSE project, due to the complexity of the backdoor code and the suspected mechanism of its exploitation, it is difficult to determine whether it has ever "triggered" on this machine, and it recommends a full OS reinstall with rotation of all relevant keys on all machines that have ever hosted infected versions of xz.

Source: linux.org.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster