In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the terminal. This could potentially result in code execution, arbitrary file writes, or other attacks.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade busybox | Nov 24, 2017 | Nov 20, 2017 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Nov 20, 2017 |
| Debian | — | Upgrade busybox | Feb 19, 2019 | Nov 20, 2017 |
| Gentoo Linux | — | Upgrade sys-apps/busybox. | Mar 27, 2018 | Nov 20, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 8, 2017 |
| Suse | — | Upgrade busyboxUpgrade busybox-static | Jan 21, 2022 | Nov 20, 2017 |
| Ubuntu | — | Upgrade busybox-initramfsUpgrade udhcpcUpgrade busyboxUpgrade udhcpdUpgrade busybox-static | Apr 10, 2019 | Nov 20, 2017 |
| Vmsa 2019 0013 | — | Upgrade VMware ESXi 6.0 to build number 14513180Upgrade VMware ESXi 6.5 to build number 13932383Upgrade VMware ESXi 6.7 to build number 13004448 | Sep 23, 2019 | Nov 20, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub