Ubuntu 24.04 Beta delayed due to malicious code in xz-utils, other Linux distros are also affected

Linux targeted by hackers
(Image credit: Pexels / OpenClipArt)

According to a Discourse post, the beta for Ubuntu 24.04 (codename: Noble Numbat) , which was due to be released tomorrow has been delayed and now we should expect it on April 11. The reason for the delay is said to be CVE-2024-3094 — otherwise known as the XZ compression tools, which were compromised with malicious code.

This delay also leads to speculation that the upcoming 24.04 launch — slated for April 25 — could possibly be delayed.

Latest Videos FromTom's Hardware
TOPICS
Les Pounder
Associate Editor

Les Pounder is an associate editor at Tom's Hardware. He is a creative technologist and for seven years has created projects to educate and inspire minds both young and old. He has worked with the Raspberry Pi Foundation to write and deliver their teacher training program "Picademy".

  • artk2219
    Admin said:
    The Ubuntu 24.04 beta has been delayed for a week due to malicious code in the xz-utils package. Updates and fixes are being worked on.

    Ubuntu 24.04 Beta delayed due to malicious code in xz-utils, other Linux distros are also affected : Read more
    I wonder who injected that code into XZ-Utils, I mean there are plenty of candidates, but I wonder who figured it was worth a go this time around.
    Reply
  • ezst036
    artk2219 said:
    I wonder who injected that code into XZ-Utils, I mean there are plenty of candidates, but I wonder who figured it was worth a go this time around.

    Some of what I have been reading (and of course its all speculative anyways) is that these were state actors, that is, someone like Russia, China, or Iran.

    As Linux continues to become more popular this sort of thing is bound to become more common.

    For the security-through-obscurity enthusiast, a *BSD is quickly becoming the only option left. Unless its a resource such as XZ, which the BSDs also rely on.
    Reply
  • Dingledooda
    Is this just a linux problem . . . . what about all the modems and routers that run linux which you know won't get updated (least the older ones)?

    Can they get into the router and then into anyone's computer connected to it now regardless of what OS it is running?
    Reply
  • CelicaGT
    artk2219 said:
    I wonder who injected that code into XZ-Utils, I mean there are plenty of candidates, but I wonder who figured it was worth a go this time around.
    https://arstechnica.com/security/2024/04/what-we-know-about-the-xz-utils-backdoor-that-almost-infected-the-world/
    This is worth a read. Quite the story, came down to ONE PERSON who noticed something funny and blew the whole operation wide open. This one should put chills down the spine of anyone working in IT security.
    Reply
  • Notton
    ezst036 said:
    that is, someone like Russia, China, or Iran.

    I think there is too little info to point fingers, but I do agree this is nation state level of malware.
    What we do know is who would have been most affected.

    Seeing as this was targeted towards Debian and Red Hat users...

    States with largest Debian share: Cuba, Czech Republic, Germany, Belarus, Russia
    States with largest Red Hat share: Bangladesh, Nepal, Sri Lanka, India, Cuba
    https://www.pingdom.com/blog/linux-popularity-across-the-globe/
    Reply
  • 35below0
    ezst036 said:
    Some of what I have been reading (and of course its all speculative anyways) is that these were state actors, that is, someone like Russia, China, or Iran.
    Don't leave out North Korea.

    But yeah, speculation only at this point.
    Reply
  • TJ Hooker
    Dingledooda said:
    Is this just a linux problem . . . . what about all the modems and routers that run linux which you know won't get updated (least the older ones)?

    Can they get into the router and then into anyone's computer connected to it now regardless of what OS it is running?
    The malicious code was only introduced in a very new release of xz utils. Highly unlikely the affected package version made it into any router FW releases.
    Reply
  • TJ Hooker
    Notton said:
    Seeing as this was targeted towards Debian and Red Hat users...
    The malicious code was introduced in the upstream xz utils source, it affects (or would have affected) any Linux distro that uses that package (so essentially all of them). Debian and Red Hat just happened to be among the first to add the new, compromised versions to their repos (just the development/beta repos though).
    Reply
  • artk2219
    CelicaGT said:
    https://arstechnica.com/security/2024/04/what-we-know-about-the-xz-utils-backdoor-that-almost-infected-the-world/
    This is worth a read. Quite the story, came down to ONE PERSON who noticed something funny and blew the whole operation wide open. This one should put chills down the spine of anyone working in IT security.
    That was a pretty fascinating read, it seems like we just got really lucky that someone was paying attention with this one.
    Reply
  • bit_user
    ezst036 said:
    Some of what I have been reading (and of course its all speculative anyways) is that these were state actors, that is, someone like Russia, China, or Iran.
    North Korea is becoming surprisingly adept at hacking. I wouldn't rule them out. Here's an awesome (free) podcast series from the BBC about the DPRK's hacking exploits:
    https://www.bbc.co.uk/programmes/w13xtvg9
    ezst036 said:
    As Linux continues to become more popular this sort of thing is bound to become more common.
    Given it's already far and away the dominant cloud OS, as well as being used for scientific and DoE (i.e. military) supercomputing, it's already a plenty juicy target. I'm actually surprised this sort of thing hasn't been happening a lot more!

    ezst036 said:
    For the security-through-obscurity enthusiast, a *BSD is quickly becoming the only option left. Unless its a resource such as XZ, which the BSDs also rely on.
    🤔
    Reply