decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade busybox | Jun 17, 2022 | Mar 19, 2021 |
| Amazon_linux | — | Upgrade busybox | May 11, 2021 | Mar 19, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Mar 19, 2021 |
| Debian | — | Upgrade busybox | Apr 5, 2021 | Mar 19, 2021 |
| Gentoo Linux | — | Upgrade sys-apps/busybox. | May 28, 2021 | Mar 19, 2021 |
| Huawei Euleros 2_0_sp9 | — | Upgrade busybox-help | Sep 29, 2021 | Mar 19, 2021 |
| Suse | — | Upgrade busybox-staticUpgrade busyboxUpgrade busybox-warewulf3Upgrade busybox-testsuite | Oct 28, 2021 | Mar 19, 2021 |
| Ubuntu | — | Upgrade busybox-initramfs (Ubuntu Pro)Upgrade busybox-staticUpgrade busybox (Ubuntu Pro)Upgrade busybox-initramfsUpgrade busyboxUpgrade busybox-static (Ubuntu Pro) | Dec 8, 2021 | Mar 19, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub