> Source: [sk182161](https://support.checkpoint.com/results/sk/sk182161)

# sk182161 - Check Point response to CVE-2024-3094

| Property | Value |
|----------|-------|
| Solution ID | sk182161 |
| Date Created | 2024-03-31 |
| Last Modified | 2024-04-01 |
| Technical Level | General |
| Products | Other |
| Versions | Not Version-Specific |

## Symptoms

- Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.  
This issue was documented under **[CVE-2024-3094](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3094)**.

## Solution

These Check Point products are **not** vulnerable:  

* Quantum on-premises products
* Quantum Spark Appliances

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
