rpm package
suse/busybox&distro=SUSE Linux Enterprise Module for Basesystem 15 SP7
pkg:rpm/suse/busybox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7
Vulnerabilities (7)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-26158 | Hig | 7.0 | < 1.37.0-150700.18.15.1 | 1.37.0-150700.18.15.1 | Feb 11, 2026 | A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or symlink entries. If the tar archive is extracted with elevated privileges, this f | |
| CVE-2026-26157 | Hig | 7.0 | < 1.37.0-150700.18.15.1 | 1.37.0-150700.18.15.1 | Feb 11, 2026 | A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file over | |
| CVE-2025-60876 | — | < 1.37.0-150700.18.10.1 | 1.37.0-150700.18.10.1 | Nov 10, 2025 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target | ||
| CVE-2025-46394 | — | < 1.37.0-150700.18.10.1 | 1.37.0-150700.18.10.1 | Apr 23, 2025 | In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences. | ||
| CVE-2023-42365 | — | < 1.37.0-150700.18.4.1 | 1.37.0-150700.18.4.1 | Nov 27, 2023 | A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar function. | ||
| CVE-2023-42364 | — | < 1.37.0-150700.18.4.1 | 1.37.0-150700.18.4.1 | Nov 27, 2023 | A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function. | ||
| CVE-2023-42363 | — | < 1.37.0-150700.18.4.1 | 1.37.0-150700.18.4.1 | Nov 27, 2023 | A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1. |
- affected < 1.37.0-150700.18.15.1fixed 1.37.0-150700.18.15.1
A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or symlink entries. If the tar archive is extracted with elevated privileges, this f
- affected < 1.37.0-150700.18.15.1fixed 1.37.0-150700.18.15.1
A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file over
- CVE-2025-60876Nov 10, 2025affected < 1.37.0-150700.18.10.1fixed 1.37.0-150700.18.10.1
BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target
- CVE-2025-46394Apr 23, 2025affected < 1.37.0-150700.18.10.1fixed 1.37.0-150700.18.10.1
In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.
- CVE-2023-42365Nov 27, 2023affected < 1.37.0-150700.18.4.1fixed 1.37.0-150700.18.4.1
A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar function.
- CVE-2023-42364Nov 27, 2023affected < 1.37.0-150700.18.4.1fixed 1.37.0-150700.18.4.1
A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function.
- CVE-2023-42363Nov 27, 2023affected < 1.37.0-150700.18.4.1fixed 1.37.0-150700.18.4.1
A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1.