Improper Handling of Exceptional Conditions in BusyBox - CVE-2021-28831
Published: March 26, 2021 / Updated: February 9, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper handling of error bit on the huft_build result pointer in decompress_gunzip.c. A remote attacker can pass malformed gzip data to the application, trigger an invalid free and perform a denial of service (DoS) attack.
Affected software
Arch Linux
Gentoo Linux
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
openSUSE Leap
openEuler
Fedora
Isolation Segment
VMware Tanzu Application Service for VMs
Juniper Cloud Native Router
SIMATIC S7-1500 TM MFP - BIOS
cflinuxfs3
SmartFabric OS10
busybox (Alpine package)
busybox (Ubuntu package)
busybox-initramfs (Ubuntu package)
busybox-static (Ubuntu package)
busybox
busybox-static
busybox-petitboot
busybox-debuginfo
busybox-help
busybox-debugsource
busybox-warewulf3
busybox-testsuite
VMware Tanzu Operations Manager
IBM QRadar Network Security
Junos cRPD
How to mitigate CVE-2021-28831
VMware Tanzu Application Service for VMs - addressed in versions 2.11.46, 2.13.28, 3.0.18, 4.0.10
cflinuxfs3 - update to 0.269.0
busybox (Alpine package) - update to 1.30.1-r5
VMware Tanzu Operations Manager - addressed in versions 2.9.39, 2.10.40, 2.10.61
IBM QRadar Network Security - addressed in versions 5.4.0.16, 5.5.0.11
busybox (Ubuntu package) - addressed in versions Ubuntu Pro, 1:1.22.015ubuntu1.4+esm1, 1:1.27.2-2ubuntu3.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-6ubuntu2.1, 1:1.30.1-6ubuntu3.1
busybox-initramfs (Ubuntu package) - addressed in versions Ubuntu Pro, 1:1.22.015ubuntu1.4+esm1, 1:1.27.2-2ubuntu3.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-6ubuntu2.1, 1:1.30.1-6ubuntu3.1
busybox-static (Ubuntu package) - addressed in versions Ubuntu Pro, 1:1.22.015ubuntu1.4+esm1, 1:1.27.2-2ubuntu3.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-6ubuntu2.1, 1:1.30.1-6ubuntu3.1
busybox - addressed in versions 1.26.2-4.5.1, 1.34.1-4.9.1, 1.35.0-4.3.1, 1.35.0-150400.3.3.1
busybox-static - addressed in versions 1.26.2-4.5.1, 1.34.1-4.9.1, 1.35.0-150400.3.3.1
busybox-petitboot - update to 1.31.1-7
busybox - update to 1.31.1-7
busybox-debuginfo - update to 1.31.1-7
busybox-help - update to 1.31.1-7
busybox-debugsource - update to 1.31.1-7
busybox - addressed in versions 1.32.1-1.fc32, 1.32.1-1.fc33, 1.33.0-3.fc34
busybox-warewulf3 - update to 1.35.0-150400.3.3.1
busybox-testsuite - update to 1.35.0-150400.3.3.1
SmartFabric OS10 - addressed in versions 10.5.4.15, 10.5.5.14, 10.5.6.9
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1
External References
Related Security Bulletins
- Denial of service in BusyBox
- Arch Linux update for busybox
- Arch Linux update for mkinitcpio-busybox
- Improper Handling of Exceptional Conditions in busybox (Alpine package)
- Amazon Linux AMI update for busybox
- Gentoo update for BusyBox
- Multiple vulnerabilities in cflinuxfs3
- Ubuntu update for busybox
- SUSE update for busybox
- Ubuntu update for busybox
- Denial of service in IBM QRadar Network Security
- VMware Tanzu products update for BusyBox
- SUSE update for busybox
- SUSE update for busybox
- SUSE update for busybox
- SUSE update for busybox
- Multiple vulnerabilities in Siemens SIMATIC S7-1500 TM MFP - BIOS
- Ubuntu update for busybox
- VMware Tanzu products update for BusyBox
- openEuler 20.03 LTS SP1 update for busybox
- Multiple vulnerabilities in Juniper Cloud Native Router
- Multiple vulnerabilities in Juniper Networks Junos cRPD
- Fedora 33 update for busybox
- Fedora 34 update for busybox
- Fedora 32 update for busybox
- Multiple vulnerabilities in Dell SmartFabric OS10
- Dell SmartFabric OS10 update for third-party components
- Dell Networking OS10 update for third-party components