# Malicious code in XZ\_jll.jl (v5.6.1+0) ; it could pose a problem?

**URL:** <https://discourse.julialang.org/t/malicious-code-in-xz-jll-jl-v5-6-1-0-it-could-pose-a-problem/112311>\
**Category:** Offtopic\
**Tags:** security\
**Created:** [March 29, 2024, 8:58pm UTC](https://discourse.julialang.org/t/malicious-code-in-xz-jll-jl-v5-6-1-0-it-could-pose-a-problem/112311 "2024-03-29T20:58:09Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ImreSamu](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/imresamu/32/20677_2.png) [@ImreSamu](https://discourse.julialang.org/u/ImreSamu)\
**Post date:** [March 29, 2024, 8:58pm UTC](https://discourse.julialang.org/t/malicious-code-in-xz-jll-jl-v5-6-1-0-it-could-pose-a-problem/112311/1 "2024-03-29T20:58:09Z")

</div>

Based on my examination of the package [https://juliahub.com/ui/Packages/General/XZ\_jll](https://juliahub.com/ui/Packages/General/XZ_jll) - XZ\_jll.jl (v5.6.1+0)  
it appears to be connected to a security issue detailed here: [https://www.phoronix.com/news/XZ-CVE-2024-3094](https://www.phoronix.com/news/XZ-CVE-2024-3094)

- _“Some malicious code was added to XZ 5.6.0/5.6.1 that could allow unauthorized remote system access.”_

This security issue is probably not critical in Julia in `XZ_jll.jl (v5.6.1+0)`,  
but could someone check if it could pose a problem?

---

<div class="post-metadata">

**Author:** ![ImreSamu](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/imresamu/32/20677_2.png) [@ImreSamu](https://discourse.julialang.org/u/ImreSamu)\
**Post date:** [March 29, 2024, 9:24pm UTC](https://discourse.julialang.org/t/malicious-code-in-xz-jll-jl-v5-6-1-0-it-could-pose-a-problem/112311/2 "2024-03-29T21:24:51Z")

</div>

Work in progress … :juliaheartpulsing: :juliaspinner: :juliaheartpulsing:

> <https://github.com/JuliaRegistries/General/pull/103876>
>
> It was reported builds of XZ v5.6.0 and v5.6.1 from release tarballs were compro…mised due to a backdoor: https://www.openwall.com/lists/oss-security/2024/03/29/4.

check:

```julia
$ docker run -it --rm julia:1.11-rc julia
               _
   _ _ _(_)_ | Documentation: https://docs.julialang.org
  (_) | (_) (_) |
   _ _ _| |_ __ _ | Type "?" for help, "]?" for Pkg help.
  | | | | | | |/ _` | |
  | | |_| | | | (_| | | Version 1.11.0-alpha2 (2024-03-18)
 _/ |\ __'_|_|_|\__'_| | Official https://julialang.org/ release
|__/ |

(@v1.11) pkg> add XZ_jll
  Installing known registries into `~/.julia`
    Updating registry at `~/.julia/registries/General.toml`
   Resolving package versions...
   Installed JLLWrappers ─ v1.5.0
   Installed XZ_jll ────── v5.4.6+0
   Installed Preferences ─ v1.4.3
    Updating `~/.julia/environments/v1.11/Project.toml`
  [ffd25f8a] + XZ_jll v5.4.6+0
    Updating `~/.julia/environments/v1.11/Manifest.toml`
  [692b3bcd] + JLLWrappers v1.5.0
  [21216c6a] + Preferences v1.4.3
  [ffd25f8a] + XZ_jll v5.4.6+0
  [56f22d72] + Artifacts v1.11.0
  [ade2ca70] + Dates v1.11.0
  [8f399da3] + Libdl v1.11.0
  [de0858da] + Printf v1.11.0
  [fa267f1f] + TOML v1.0.3
  [4ec0a83e] + Unicode v1.11.0
Precompiling project...
  3 dependencies successfully precompiled in 4 seconds. 4 already precompiled.

```

---

<div class="post-metadata">

**Author:** ![ImreSamu](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/imresamu/32/20677_2.png) [@ImreSamu](https://discourse.julialang.org/u/ImreSamu)\
**Post date:** [March 29, 2024, 10:06pm UTC](https://discourse.julialang.org/t/malicious-code-in-xz-jll-jl-v5-6-1-0-it-could-pose-a-problem/112311/3 "2024-03-29T22:06:26Z")

</div>

Related julia codes ( by github search )

- 5.6.1+0 → now : 229 files  
[`XZ_jll "ffd25f8a-64ca-5728-b0f7-c24cf3aae800" "version =" "5.6.1+0"`](https://github.com/search?q=XZ_jll++%22ffd25f8a-64ca-5728-b0f7-c24cf3aae800%22+%22version+%3D%22+%225.6.1%2B0%22&type=code)

- 5.6.0+0 → now: 104 files  
[`"XZ_jll "ffd25f8a-64ca-5728-b0f7-c24cf3aae800" "version =" "5.6.0+0"`](https://github.com/search?q=XZ_jll++%22ffd25f8a-64ca-5728-b0f7-c24cf3aae800%22+%22version+%3D%22+%225.6.0%2B0%22&type=code)

---

<div class="post-metadata">

**Author:** ![giordano](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/giordano/32/2166_2.png) [@giordano](https://discourse.julialang.org/u/giordano)\
**Post date:** [March 30, 2024, 12:41pm UTC](https://discourse.julialang.org/t/malicious-code-in-xz-jll-jl-v5-6-1-0-it-could-pose-a-problem/112311/4 "2024-03-30T12:41:02Z")

</div>

> [@PSA: backdoor in xz-utils and relevance for the Julia ecosystem](https://discourse.julialang.org/t/psa-backdoor-in-xz-utils-and-relevance-for-the-julia-ecosystem/112328):
>
> Statement of the problem A [thread in oss-security](https://www.openwall.com/lists/oss-security/2024/03/29/4) mailing list reported that the [XZ Utils](https://en.wikipedia.org/wiki/XZ_Utils) project was affected by a [backdoor](https://en.wikipedia.org/wiki/Backdoor_(computing)): one of the current maintainers of the project appeared to have injected malicious code, included in versions v5.6.0 and v5.6.1 of the xz-utils package, that under certain circumstances could potentially compromise an OpenSSH client and obtain login credentials to remote systems. Affected systems and conditions for the backdoor to work XZ Utils is somewhat popular in Linu…
