Skip to content
  • GDPR-compliant
  • 100% hosting in Germany
  • Personal contact
  • Support included
  • Provisioning within 24 hours
Security warnings 3 min read

Important security notice: Current situation regarding the XZ backdoor

In the world of IT security, vigilance is paramount. A recently discovered vulnerability has set alarm bells ringing in the Linux community. It is a critical backdoor in the ‘XZ’ tools and libraries, specifically in…

xz backdoor Linux

In the world of IT security, vigilance is paramount. A recently discovered vulnerability has set the Linux community on high alert. It is a critical backdoor in the ‘XZ’ tools and libraries, specifically in versions 5.6.0 and 5.6.1. This backdoor, published as CVE-2024-3094, makes it possible to bypass authentication via sshd using systemd. Such an exploit poses a serious security risk, as it can allow unauthorised access to the system via the SSH protocol.

The BSI has issued a Level 3 / Orange security alert regarding this:

BSI Publication - Critical backdoor in XZ for Linux (external link)

It is important to note that this vulnerability has only been found in the download packages for these specific versions. The Git distributions are not affected, as the macro responsible for activating the malicious code is missing from them. So far, within the Red Hat family, only Fedora 41 and Fedora Rawhide have been reported as affected. Red Hat Enterprise Linux (RHEL) and its distributions are not affected according to current information. Nevertheless, there is a possibility that other Linux distributions could be at risk.

Background and current status

A blog post (external link) by the security experts at Tenable provides a list of the Linux distributions and their versions that, according to current information, are affected by the vulnerability. The distributions mentioned include Arch Linux, Debian (in the testing, unstable and experimental versions), Kali Linux, OpenSUSE MicroOS and Tumbleweed, as well as Fedora 40 Beta, 41 and Rawhide from Red Hat.

Our measures to ensure security

At SpeedIT Solutions, we take every threat to IT security seriously. As soon as the news came to light, we carried out a thorough review of our Managed Cloud and Managed Hosting systems. We can confirm that, based on current information and a thorough investigation, our systems are not affected by this backdoor. Our customers can rest assured that their data and services remain protected.

Recommendations for customers with dedicated & self-managed cloud servers

For customers operating dedicated and self-managed cloud servers, we strongly recommend that you check your systems immediately for this potential vulnerability. In particular, if you are using Fedora 41 or Fedora Rawhide, you should take the following action:

  1. Stop using the affected Fedora versions as soon as possible.
  2. Roll back XZ to an older, stable version such as 5.4.6. SUSE has already published a downgrade procedure which you can follow.
  3. Avoid upgrading to XZ versions 5.6.x or revert to secure versions if you have already updated.

Assistance from our support team

We understand that such security alerts can cause uncertainty. That is why we are on hand to offer support and advice. Should you require assistance in checking your systems or implementing the recommended steps, please do not hesitate to contact us. Together, we can ensure that your digital infrastructure is protected against current and future threats.

More posts

All posts
General 3 min read

SpeedIT nominated once again: Web Host of the Year 2026

We are delighted to announce that SpeedIT Solutions has once again been nominated for the prestigious ‘Web Host of the Year’ award in 2026 - in no fewer than three categories: Managed Servers, Shop Hosting and CMS Hosting…

Domains 6 min read

NIS-2 at DENIC: What will change for your .de domain from 14 April 2026

Since 14 April 2026, new, binding rules have been in force at DENIC eG for all .de domains. This follows on from the European NIS 2 Directive, which aims to ensure greater security, transparency and data quality in domain registrations across the EU…