rpm package
opensuse/busybox&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/busybox&distro=openSUSE%20Tumbleweed
Vulnerabilities (41)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-88839 | Med | 6.7 | < 1.38.0-3.1 | 1.38.0-3.1 | Sep 23, 2026 | BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers. | |
| CVE-2026-88837 | Med | 6.5 | < 1.38.0-3.1 | 1.38.0-3.1 | Sep 23, 2026 | BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authentication check. | |
| CVE-2026-88835 | Med | 6.1 | < 1.38.0-3.1 | 1.38.0-3.1 | Sep 23, 2026 | BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read. | |
| CVE-2026-88831 | Med | 5.3 | < 1.38.0-3.1 | 1.38.0-3.1 | Sep 23, 2026 | BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no clients. | |
| CVE-2026-88832 | Hig | 7.3 | < 1.38.0-3.1 | 1.38.0-3.1 | Sep 23, 2026 | BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images. | |
| CVE-2026-88830 | Hig | 7.5 | < 1.38.0-3.1 | 1.38.0-3.1 | Sep 23, 2026 | A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow when processing a crafted ClientKeyExchange message. | |
| CVE-2026-88841 | low | 3.3 | < 1.38.0-3.1 | 1.38.0-3.1 | Sep 23, 2026 | busybox: busybox: dpkg write_status_file() stale cursor causes out-of-bounds read and status file corruption | |
| CVE-2026-38755 | Low | 2.9 | < 1.38.0-2.1 | 1.38.0-2.1 | Jul 15, 2026 | A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. | |
| CVE-2026-38754 | Med | 5.1 | < 1.38.0-2.1 | 1.38.0-2.1 | Jul 15, 2026 | A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. | |
| CVE-2026-38752 | Low | 2.9 | < 1.38.0-2.1 | 1.38.0-2.1 | Jul 15, 2026 | A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. | |
| CVE-2026-38753 | Med | 4.9 | < 1.38.0-2.1 | 1.38.0-2.1 | Jul 15, 2026 | A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. | |
| CVE-2026-29004 | Hig | 8.1 | < 1.37.0-11.1 | 1.37.0-11.1 | May 4, 2026 | BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhcpc.c that allows network-adjacent attackers to trigger memory corruption by sending a crafted DHCPv6 response with a mal | |
| CVE-2026-26158 | Hig | 7.0 | < 1.37.0-9.1 | 1.37.0-9.1 | Feb 11, 2026 | A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or symlink entries. If the tar archive is extracted with elevated privileges, this f | |
| CVE-2026-26157 | Hig | 7.0 | < 1.37.0-10.1 | 1.37.0-10.1 | Feb 11, 2026 | A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file over | |
| CVE-2025-60876 | Med | 6.5 | < 1.37.0-8.1 | 1.37.0-8.1 | Nov 10, 2025 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target | |
| CVE-2025-46394 | Low | 3.2 | < 1.37.0-8.1 | 1.37.0-8.1 | Apr 23, 2025 | In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences. | |
| CVE-2023-42366 | Med | 5.5 | < 1.38.0-2.1 | 1.38.0-2.1 | Nov 27, 2023 | A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159. | |
| CVE-2023-42365 | Med | 5.5 | < 1.37.0-5.1 | 1.37.0-5.1 | Nov 27, 2023 | A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar function. | |
| CVE-2023-42364 | Med | 5.5 | < 1.37.0-5.1 | 1.37.0-5.1 | Nov 27, 2023 | A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function. | |
| CVE-2023-42363 | Med | 5.5 | < 1.37.0-5.1 | 1.37.0-5.1 | Nov 27, 2023 | A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1. |
- affected < 1.38.0-3.1fixed 1.38.0-3.1
BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers.
- affected < 1.38.0-3.1fixed 1.38.0-3.1
BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authentication check.
- affected < 1.38.0-3.1fixed 1.38.0-3.1
BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read.
- affected < 1.38.0-3.1fixed 1.38.0-3.1
BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no clients.
- affected < 1.38.0-3.1fixed 1.38.0-3.1
BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images.
- affected < 1.38.0-3.1fixed 1.38.0-3.1
A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow when processing a crafted ClientKeyExchange message.
- affected < 1.38.0-3.1fixed 1.38.0-3.1
busybox: busybox: dpkg write_status_file() stale cursor causes out-of-bounds read and status file corruption
- affected < 1.38.0-2.1fixed 1.38.0-2.1
A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
- affected < 1.38.0-2.1fixed 1.38.0-2.1
A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
- affected < 1.38.0-2.1fixed 1.38.0-2.1
A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
- affected < 1.38.0-2.1fixed 1.38.0-2.1
A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
- affected < 1.37.0-11.1fixed 1.37.0-11.1
BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhcpc.c that allows network-adjacent attackers to trigger memory corruption by sending a crafted DHCPv6 response with a mal
- affected < 1.37.0-9.1fixed 1.37.0-9.1
A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or symlink entries. If the tar archive is extracted with elevated privileges, this f
- affected < 1.37.0-10.1fixed 1.37.0-10.1
A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file over
- affected < 1.37.0-8.1fixed 1.37.0-8.1
BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target
- affected < 1.37.0-8.1fixed 1.37.0-8.1
In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.
- affected < 1.38.0-2.1fixed 1.38.0-2.1
A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159.
- affected < 1.37.0-5.1fixed 1.37.0-5.1
A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar function.
- affected < 1.37.0-5.1fixed 1.37.0-5.1
A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function.
- affected < 1.37.0-5.1fixed 1.37.0-5.1
A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1.
Page 1 of 3