The get_next_block function in archival/libarchive/decompress_bunzip2.c in BusyBox 1.27.2 has an Integer Overflow that may lead to a write access violation.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade busybox | Nov 24, 2017 | Oct 24, 2017 |
| Debian | — | Upgrade busybox | Feb 19, 2019 | Oct 24, 2017 |
| Gentoo Linux | — | Upgrade sys-apps/busybox. | Mar 27, 2018 | Oct 24, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 22, 2017 |
| Suse | — | Upgrade busybox-staticUpgrade busybox | Jan 21, 2022 | Oct 24, 2017 |
| Ubuntu | — | Upgrade busyboxUpgrade busybox-staticUpgrade busybox-initramfsUpgrade udhcpdUpgrade udhcpc | Apr 10, 2019 | Oct 24, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub