# Advisory on CVE-2024-3094

## Backdoor in XZ Utils

On March 29, 2024, the Openwall oss-security [<mark style="color:blue;">mailing list</mark>](https://www.openwall.com/lists/oss-security/2024/03/29/4) published information about a backdoor in the compression **utility/library xz/liblzma**. This backdoor affects `sshd` in some rolling and testing **Linux** distributions. The CVE ID [<mark style="color:blue;">CVE-2024-3094</mark>](https://nvd.nist.gov/vuln/detail/CVE-2024-3094) is assigned to this vulnerability and has a **Critical** severity with Common Vulnerability Scoring System (CVSS) of **10 score**.

For more information, refer to the official [<mark style="color:blue;">Red Hat Blog</mark>](https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users).

## Impacted IONOS Cloud products

IONOS Cloud infrastructure and services do not utilize the vulnerable software, so they are not impacted.

## What action can you take to mitigate the vulnerability?

If you are using custom images, we advise you to refer to the information provided by the Operating System (OS) vendor to address any concerns from this reported issue.

## How can I get help?

If you have further questions or concerns about this vulnerability, contact [<mark style="color:blue;">IONOS Cloud Support</mark>](https://docs.ionos.com/cloud/support/general-information/contact-information).
