In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the terminal. This could potentially result in code execution, arbitrary file writes, or other attacks.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-busybox | Nov 24, 2017 | Nov 20, 2017 | |
| Arch Linux | View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗ | arch-linux-upgrade-latest | Jul 11, 2025 | Nov 20, 2017 |
| Debian | debian-upgrade-busybox | Feb 19, 2019 | Nov 20, 2017 | |
| Gentoo Linux | gentoo-linux-upgrade-sys-apps-busybox | Mar 27, 2018 | Nov 20, 2017 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Nov 8, 2017 | |
| Suse | — | suse-upgrade-busyboxsuse-upgrade-busybox-static | Jan 21, 2022 | Nov 20, 2017 |
| Ubuntu | ubuntu-upgrade-busyboxubuntu-upgrade-busybox-initramfsubuntu-upgrade-busybox-staticubuntu-upgrade-udhcpcubuntu-upgrade-udhcpd | Apr 10, 2019 | Nov 20, 2017 | |
| Vmsa 2019 0013 | vmware-esxi60-upgrade-14513180vmware-esxi65-upgrade-13932383vmware-esxi67-upgrade-13004448 | Sep 23, 2019 | Nov 20, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub