#vulns.co
/
mcp by GKData.io

← Back to Reports

Malicious upstream code in xz Utils

This record is about provenance, not just patching. A dependency can be correctly named and versioned while its release process has become the trust failure. Mature response combines package inventory with distribution provenance, reproducible-build signals…

Editorial decision card. This page links to a source-verified public disclosure and contains only original defensive analysis. It does not mirror upstream HTML, payloads, attachments, private submissions, or exploit steps.
Original severity
critical; CVSS 10.0 source-reported; not rescored by vulns.co
Public source
github advisory
Program / vendor
xz Utils project
Product / surface
xz upstream release artifacts and dependent Linux distributions
Weakness
Embedded malicious code in a software supply-chain release · CWE-506
Affected boundary
upstream release to downstream distribution boundary
Disclosure date
2024-03-29
Public status checked
2026-09-10

What the evidence established

The public advisory documents malicious code in specific upstream release artifacts rather than an ordinary accidental implementation defect.

Why the impact was credible

The source rates the issue Critical with CVSS 10.0; downstream provenance and build lineage were central to determining exposure.

Durable engineering lesson

This record is about provenance, not just patching. A dependency can be correctly named and versioned while its release process has become the trust failure. Mature response combines package inventory with distribution provenance, reproducible-build signals where available, and a review path for sudden maintainer or build-system changes.

Control pattern

Identify deployed package provenance, replace affected artifacts with trusted fixed distributions, and strengthen release verification and maintainer-change review.

Primary public disclosure

Read the original source ↗

Upstream availability and wording can change. Public status was last checked 2026-09-10.

← Back to Reports