Out-of-bounds read in BusyBox - CVE-2021-42374
Published: December 8, 2021
Vulnerability identifier: #VU58670
CSH Severity: Medium
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-42374
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition in "unlzma". A remote attacker can trigger out-of-bounds read error and read contents of memory on the system or perform a denial of service (DoS) attack.
Affected software
BusyBox
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
openSUSE Leap
Ubuntu
openEuler
Fedora
SIMATIC S7-1500 TM MFP - BIOS
SINAMICS GL150
SINAMICS SL150
SINAMICS PERFECT HARMONY GH180 6SR5
SCALANCE S615
cflinuxfs3
busybox (Ubuntu package)
busybox-static (Ubuntu package)
busybox-initramfs (Ubuntu package)
busybox-debuginfo
busybox-petitboot
busybox-debugsource
busybox-help
busybox
sys-apps/busybox
busybox-static
busybox-warewulf3
busybox-testsuite
SCALANCE WAM766-1 (EU)
SCALANCE WUM766-1 (US)
SCALANCE WUM766-1 (EU)
SCALANCE WUM763-1
SCALANCE WAM766-1 EEC (US)
SCALANCE WAM766-1 EEC (EU)
SCALANCE WAM766-1 (US)
SCALANCE WAM763-1
SCALANCE M876-3 (EVDO)
SCALANCE M812-1 ADSL-Router (Annex A)
SCALANCE M812-1 ADSL-Router (Annex B)
SCALANCE M816-1 ADSL-Router (Annex A)
SCALANCE M816-1 ADSL-Router (Annex B)
SCALANCE M826-2 SHDSL-Router
SCALANCE M874-2
RUGGEDCOM RM1224 LTE(4G) EU
RUGGEDCOM RM1224 LTE(4G) NAM
SCALANCE M874-3
SCALANCE S615 EEC
SCALANCE M876-3 (ROK)
SCALANCE M876-4
SCALANCE M876-4 (EU)
SCALANCE M876-4 (NAM)
SCALANCE MUM853-1 (EU)
SCALANCE MUM856-1 (EU)
SCALANCE MUM856-1 (RoW)
SCALANCE M804PB
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
openSUSE Leap
Ubuntu
openEuler
Fedora
SIMATIC S7-1500 TM MFP - BIOS
SINAMICS GL150
SINAMICS SL150
SINAMICS PERFECT HARMONY GH180 6SR5
SCALANCE S615
cflinuxfs3
busybox (Ubuntu package)
busybox-static (Ubuntu package)
busybox-initramfs (Ubuntu package)
busybox-debuginfo
busybox-petitboot
busybox-debugsource
busybox-help
busybox
sys-apps/busybox
busybox-static
busybox-warewulf3
busybox-testsuite
SCALANCE WAM766-1 (EU)
SCALANCE WUM766-1 (US)
SCALANCE WUM766-1 (EU)
SCALANCE WUM763-1
SCALANCE WAM766-1 EEC (US)
SCALANCE WAM766-1 EEC (EU)
SCALANCE WAM766-1 (US)
SCALANCE WAM763-1
SCALANCE M876-3 (EVDO)
SCALANCE M812-1 ADSL-Router (Annex A)
SCALANCE M812-1 ADSL-Router (Annex B)
SCALANCE M816-1 ADSL-Router (Annex A)
SCALANCE M816-1 ADSL-Router (Annex B)
SCALANCE M826-2 SHDSL-Router
SCALANCE M874-2
RUGGEDCOM RM1224 LTE(4G) EU
RUGGEDCOM RM1224 LTE(4G) NAM
SCALANCE M874-3
SCALANCE S615 EEC
SCALANCE M876-3 (ROK)
SCALANCE M876-4
SCALANCE M876-4 (EU)
SCALANCE M876-4 (NAM)
SCALANCE MUM853-1 (EU)
SCALANCE MUM856-1 (EU)
SCALANCE MUM856-1 (RoW)
SCALANCE M804PB
How to mitigate CVE-2021-42374
Install updates from vendor's website.
BusyBox - update to 1.34.0
cflinuxfs3 - update to 0.269.0
busybox (Ubuntu package) - addressed in versions 1:1.27.2-2ubuntu3.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-6ubuntu2.1, 1:1.30.1-6ubuntu3.1
busybox-static (Ubuntu package) - addressed in versions 1:1.27.2-2ubuntu3.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-6ubuntu2.1, 1:1.30.1-6ubuntu3.1
busybox-initramfs (Ubuntu package) - addressed in versions 1:1.27.2-2ubuntu3.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-6ubuntu2.1, 1:1.30.1-6ubuntu3.1
busybox-debuginfo - update to 1.31.1-10
busybox-petitboot - update to 1.31.1-10
busybox-debugsource - update to 1.31.1-10
busybox-help - update to 1.31.1-10
busybox - update to 1.31.1-10
sys-apps/busybox - update to 1.34.0
busybox - addressed in versions 1.34.1-1.fc33, 1.34.1-1.fc34
busybox - addressed in versions 1.34.1-4.9.1, 1.35.0-4.3.1, 1.35.0-150400.3.3.1
busybox-static - addressed in versions 1.34.1-4.9.1, 1.35.0-150400.3.3.1
busybox-warewulf3 - update to 1.35.0-150400.3.3.1
busybox-testsuite - update to 1.35.0-150400.3.3.1
SCALANCE WAM766-1 (EU) - update to 2.0
SCALANCE WUM766-1 (US) - update to 2.0
SCALANCE WUM766-1 (EU) - update to 2.0
SCALANCE WUM763-1 - update to 2.0
SCALANCE WAM766-1 EEC (US) - update to 2.0
SCALANCE WAM766-1 EEC (EU) - update to 2.0
SCALANCE WAM766-1 (US) - update to 2.0
SCALANCE WAM763-1 - update to 2.0
SCALANCE M876-3 (EVDO) - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M826-2 SHDSL-Router - update to 7.2
SCALANCE M874-2 - update to 7.2
RUGGEDCOM RM1224 LTE(4G) EU - update to 7.2
RUGGEDCOM RM1224 LTE(4G) NAM - update to 7.2
SCALANCE S615 - update to 7.2
SCALANCE M874-3 - update to 7.2
SCALANCE S615 EEC - update to 7.2
SCALANCE M876-3 (ROK) - update to 7.2
SCALANCE M876-4 - update to 7.2
SCALANCE M876-4 (EU) - update to 7.2
SCALANCE M876-4 (NAM) - update to 7.2
SCALANCE MUM853-1 (EU) - update to 7.2
SCALANCE MUM856-1 (EU) - update to 7.2
SCALANCE MUM856-1 (RoW) - update to 7.2
SCALANCE M804PB - update to 7.2
cflinuxfs3 - update to 0.269.0
busybox (Ubuntu package) - addressed in versions 1:1.27.2-2ubuntu3.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-6ubuntu2.1, 1:1.30.1-6ubuntu3.1
busybox-static (Ubuntu package) - addressed in versions 1:1.27.2-2ubuntu3.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-6ubuntu2.1, 1:1.30.1-6ubuntu3.1
busybox-initramfs (Ubuntu package) - addressed in versions 1:1.27.2-2ubuntu3.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-6ubuntu2.1, 1:1.30.1-6ubuntu3.1
busybox-debuginfo - update to 1.31.1-10
busybox-petitboot - update to 1.31.1-10
busybox-debugsource - update to 1.31.1-10
busybox-help - update to 1.31.1-10
busybox - update to 1.31.1-10
sys-apps/busybox - update to 1.34.0
busybox - addressed in versions 1.34.1-1.fc33, 1.34.1-1.fc34
busybox - addressed in versions 1.34.1-4.9.1, 1.35.0-4.3.1, 1.35.0-150400.3.3.1
busybox-static - addressed in versions 1.34.1-4.9.1, 1.35.0-150400.3.3.1
busybox-warewulf3 - update to 1.35.0-150400.3.3.1
busybox-testsuite - update to 1.35.0-150400.3.3.1
SCALANCE WAM766-1 (EU) - update to 2.0
SCALANCE WUM766-1 (US) - update to 2.0
SCALANCE WUM766-1 (EU) - update to 2.0
SCALANCE WUM763-1 - update to 2.0
SCALANCE WAM766-1 EEC (US) - update to 2.0
SCALANCE WAM766-1 EEC (EU) - update to 2.0
SCALANCE WAM766-1 (US) - update to 2.0
SCALANCE WAM763-1 - update to 2.0
SCALANCE M876-3 (EVDO) - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M826-2 SHDSL-Router - update to 7.2
SCALANCE M874-2 - update to 7.2
RUGGEDCOM RM1224 LTE(4G) EU - update to 7.2
RUGGEDCOM RM1224 LTE(4G) NAM - update to 7.2
SCALANCE S615 - update to 7.2
SCALANCE M874-3 - update to 7.2
SCALANCE S615 EEC - update to 7.2
SCALANCE M876-3 (ROK) - update to 7.2
SCALANCE M876-4 - update to 7.2
SCALANCE M876-4 (EU) - update to 7.2
SCALANCE M876-4 (NAM) - update to 7.2
SCALANCE MUM853-1 (EU) - update to 7.2
SCALANCE MUM856-1 (EU) - update to 7.2
SCALANCE MUM856-1 (RoW) - update to 7.2
SCALANCE M804PB - update to 7.2
External References
- https://jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-claroty-and-jfrog/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6T2TURBYYJGBMQTTN2DSOAIQGP7WCPGV/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UQXGOGWBIYWOIVXJVRKHZR34UMEHQBXS/
Related Security Bulletins
- Multiple vulnerabilities in BusyBox
- Multiple vulnerabilities in cflinuxfs3
- Ubuntu update for busybox
- SUSE update for busybox
- SUSE update for busybox
- Multiple vulnerabilities in Siemens RUGGEDCOM and SCALANCE Products
- Multiple vulnerabilities in Siemens SCALANCE W-700 IEEE 802.11ax devices
- SUSE update for busybox
- SUSE update for busybox
- Multiple vulnerabilities in Siemens SIMATIC S7-1500 TM MFP - BIOS
- Multiple vulnerabilities in Siemens Integrated SCALANCE S615 of SINAMICS Medium Voltage products
- openEuler update for busybox
- Gentoo update for BusyBox
- Fedora 34 update for busybox
- Fedora 33 update for busybox