Malicious upstream code in xz Utils
This record is about provenance, not just patching. A dependency can be correctly named and versioned while its release process has become the trust failure. Mature response combines package inventory with distribution provenance, reproducible-build signals…
- Original severity
- critical; CVSS 10.0 source-reported; not rescored by vulns.co
- Public source
- github advisory
- Program / vendor
- xz Utils project
- Product / surface
- xz upstream release artifacts and dependent Linux distributions
- Weakness
- Embedded malicious code in a software supply-chain release · CWE-506
- Affected boundary
- upstream release to downstream distribution boundary
- Disclosure date
- 2024-03-29
- Public status checked
- 2026-09-10
What the evidence established
The public advisory documents malicious code in specific upstream release artifacts rather than an ordinary accidental implementation defect.
Why the impact was credible
The source rates the issue Critical with CVSS 10.0; downstream provenance and build lineage were central to determining exposure.
Durable engineering lesson
This record is about provenance, not just patching. A dependency can be correctly named and versioned while its release process has become the trust failure. Mature response combines package inventory with distribution provenance, reproducible-build signals where available, and a review path for sudden maintainer or build-system changes.
Control pattern
Identify deployed package provenance, replace affected artifacts with trusted fixed distributions, and strengthen release verification and maintainer-change review.
Primary public disclosure
Upstream availability and wording can change. Public status was last checked 2026-09-10.