Use-after-free in BusyBox - CVE-2021-42378
Published: December 8, 2021
Vulnerability identifier: #VU58680
CSH Severity: Low
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-42378
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to compromise vulnerable system.
The vulnerability exists due to a use-after-free error in the "getvar_i" function. A remote administrator can execute arbitrary code on the target system.
Affected software
BusyBox
Gentoo Linux
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
openSUSE Leap
Ubuntu
openEuler
Fedora
SIMATIC S7-1500 TM MFP - BIOS
SINAMICS GL150
SINAMICS SL150
SINAMICS PERFECT HARMONY GH180 6SR5
SCALANCE S615
cflinuxfs3
SmartFabric OS10
busybox (Ubuntu package)
busybox-static (Ubuntu package)
busybox-initramfs (Ubuntu package)
busybox
busybox-help
busybox-petitboot
busybox-debuginfo
busybox-debugsource
sys-apps/busybox
busybox-static
busybox-warewulf3
busybox-testsuite
SCALANCE WAM766-1 (EU)
SCALANCE WAM763-1
SCALANCE WAM766-1 (US)
SCALANCE WAM766-1 EEC (EU)
SCALANCE WAM766-1 EEC (US)
SCALANCE WUM763-1
SCALANCE WUM766-1 (EU)
SCALANCE WUM766-1 (US)
SCALANCE M876-4 (EU)
RUGGEDCOM RM1224 LTE(4G) EU
RUGGEDCOM RM1224 LTE(4G) NAM
SCALANCE M804PB
SCALANCE M812-1 ADSL-Router (Annex A)
SCALANCE M812-1 ADSL-Router (Annex B)
SCALANCE M816-1 ADSL-Router (Annex A)
SCALANCE M816-1 ADSL-Router (Annex B)
SCALANCE M826-2 SHDSL-Router
SCALANCE M874-2
SCALANCE M874-3
SCALANCE M876-3 (EVDO)
SCALANCE M876-3 (ROK)
SCALANCE M876-4
SCALANCE M876-4 (NAM)
SCALANCE MUM853-1 (EU)
SCALANCE MUM856-1 (EU)
SCALANCE MUM856-1 (RoW)
SCALANCE S615 EEC
Gentoo Linux
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
openSUSE Leap
Ubuntu
openEuler
Fedora
SIMATIC S7-1500 TM MFP - BIOS
SINAMICS GL150
SINAMICS SL150
SINAMICS PERFECT HARMONY GH180 6SR5
SCALANCE S615
cflinuxfs3
SmartFabric OS10
busybox (Ubuntu package)
busybox-static (Ubuntu package)
busybox-initramfs (Ubuntu package)
busybox
busybox-help
busybox-petitboot
busybox-debuginfo
busybox-debugsource
sys-apps/busybox
busybox-static
busybox-warewulf3
busybox-testsuite
SCALANCE WAM766-1 (EU)
SCALANCE WAM763-1
SCALANCE WAM766-1 (US)
SCALANCE WAM766-1 EEC (EU)
SCALANCE WAM766-1 EEC (US)
SCALANCE WUM763-1
SCALANCE WUM766-1 (EU)
SCALANCE WUM766-1 (US)
SCALANCE M876-4 (EU)
RUGGEDCOM RM1224 LTE(4G) EU
RUGGEDCOM RM1224 LTE(4G) NAM
SCALANCE M804PB
SCALANCE M812-1 ADSL-Router (Annex A)
SCALANCE M812-1 ADSL-Router (Annex B)
SCALANCE M816-1 ADSL-Router (Annex A)
SCALANCE M816-1 ADSL-Router (Annex B)
SCALANCE M826-2 SHDSL-Router
SCALANCE M874-2
SCALANCE M874-3
SCALANCE M876-3 (EVDO)
SCALANCE M876-3 (ROK)
SCALANCE M876-4
SCALANCE M876-4 (NAM)
SCALANCE MUM853-1 (EU)
SCALANCE MUM856-1 (EU)
SCALANCE MUM856-1 (RoW)
SCALANCE S615 EEC
How to mitigate CVE-2021-42378
Install updates from vendor's website.
BusyBox - update to 1.34.0
cflinuxfs3 - update to 0.269.0
busybox (Ubuntu package) - addressed in versions 1:1.27.2-2ubuntu3.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-6ubuntu2.1, 1:1.30.1-6ubuntu3.1
busybox-static (Ubuntu package) - addressed in versions 1:1.27.2-2ubuntu3.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-6ubuntu2.1, 1:1.30.1-6ubuntu3.1
busybox-initramfs (Ubuntu package) - addressed in versions 1:1.27.2-2ubuntu3.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-6ubuntu2.1, 1:1.30.1-6ubuntu3.1
busybox - update to 1.31.1-13
busybox-help - update to 1.31.1-13
busybox-petitboot - update to 1.31.1-13
busybox-debuginfo - update to 1.31.1-13
busybox-debugsource - update to 1.31.1-13
sys-apps/busybox - update to 1.34.0
busybox - addressed in versions 1.34.1-1.fc33, 1.34.1-1.fc34
busybox-static - addressed in versions 1.34.1-4.9.1, 1.35.0-150400.3.3.1
busybox - addressed in versions 1.34.1-4.9.1, 1.35.0-4.3.1, 1.35.0-150400.3.3.1
busybox-warewulf3 - update to 1.35.0-150400.3.3.1
busybox-testsuite - update to 1.35.0-150400.3.3.1
SCALANCE WAM766-1 (EU) - update to 2.0
SCALANCE WAM763-1 - update to 2.0
SCALANCE WAM766-1 (US) - update to 2.0
SCALANCE WAM766-1 EEC (EU) - update to 2.0
SCALANCE WAM766-1 EEC (US) - update to 2.0
SCALANCE WUM763-1 - update to 2.0
SCALANCE WUM766-1 (EU) - update to 2.0
SCALANCE WUM766-1 (US) - update to 2.0
SCALANCE S615 - update to 7.2
SCALANCE M876-4 (EU) - update to 7.2
RUGGEDCOM RM1224 LTE(4G) EU - update to 7.2
RUGGEDCOM RM1224 LTE(4G) NAM - update to 7.2
SCALANCE M804PB - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M826-2 SHDSL-Router - update to 7.2
SCALANCE M874-2 - update to 7.2
SCALANCE M874-3 - update to 7.2
SCALANCE M876-3 (EVDO) - update to 7.2
SCALANCE M876-3 (ROK) - update to 7.2
SCALANCE M876-4 - update to 7.2
SCALANCE M876-4 (NAM) - update to 7.2
SCALANCE MUM853-1 (EU) - update to 7.2
SCALANCE MUM856-1 (EU) - update to 7.2
SCALANCE MUM856-1 (RoW) - update to 7.2
SCALANCE S615 EEC - update to 7.2
SmartFabric OS10 - addressed in versions 10.5.4.15, 10.5.5.14, 10.5.6.9
cflinuxfs3 - update to 0.269.0
busybox (Ubuntu package) - addressed in versions 1:1.27.2-2ubuntu3.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-6ubuntu2.1, 1:1.30.1-6ubuntu3.1
busybox-static (Ubuntu package) - addressed in versions 1:1.27.2-2ubuntu3.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-6ubuntu2.1, 1:1.30.1-6ubuntu3.1
busybox-initramfs (Ubuntu package) - addressed in versions 1:1.27.2-2ubuntu3.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-6ubuntu2.1, 1:1.30.1-6ubuntu3.1
busybox - update to 1.31.1-13
busybox-help - update to 1.31.1-13
busybox-petitboot - update to 1.31.1-13
busybox-debuginfo - update to 1.31.1-13
busybox-debugsource - update to 1.31.1-13
sys-apps/busybox - update to 1.34.0
busybox - addressed in versions 1.34.1-1.fc33, 1.34.1-1.fc34
busybox-static - addressed in versions 1.34.1-4.9.1, 1.35.0-150400.3.3.1
busybox - addressed in versions 1.34.1-4.9.1, 1.35.0-4.3.1, 1.35.0-150400.3.3.1
busybox-warewulf3 - update to 1.35.0-150400.3.3.1
busybox-testsuite - update to 1.35.0-150400.3.3.1
SCALANCE WAM766-1 (EU) - update to 2.0
SCALANCE WAM763-1 - update to 2.0
SCALANCE WAM766-1 (US) - update to 2.0
SCALANCE WAM766-1 EEC (EU) - update to 2.0
SCALANCE WAM766-1 EEC (US) - update to 2.0
SCALANCE WUM763-1 - update to 2.0
SCALANCE WUM766-1 (EU) - update to 2.0
SCALANCE WUM766-1 (US) - update to 2.0
SCALANCE S615 - update to 7.2
SCALANCE M876-4 (EU) - update to 7.2
RUGGEDCOM RM1224 LTE(4G) EU - update to 7.2
RUGGEDCOM RM1224 LTE(4G) NAM - update to 7.2
SCALANCE M804PB - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M826-2 SHDSL-Router - update to 7.2
SCALANCE M874-2 - update to 7.2
SCALANCE M874-3 - update to 7.2
SCALANCE M876-3 (EVDO) - update to 7.2
SCALANCE M876-3 (ROK) - update to 7.2
SCALANCE M876-4 - update to 7.2
SCALANCE M876-4 (NAM) - update to 7.2
SCALANCE MUM853-1 (EU) - update to 7.2
SCALANCE MUM856-1 (EU) - update to 7.2
SCALANCE MUM856-1 (RoW) - update to 7.2
SCALANCE S615 EEC - update to 7.2
SmartFabric OS10 - addressed in versions 10.5.4.15, 10.5.5.14, 10.5.6.9
External References
- https://jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-claroty-and-jfrog/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6T2TURBYYJGBMQTTN2DSOAIQGP7WCPGV/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UQXGOGWBIYWOIVXJVRKHZR34UMEHQBXS/
Related Security Bulletins
- Multiple vulnerabilities in BusyBox
- Multiple vulnerabilities in cflinuxfs3
- Amazon Linux AMI update for busybox
- Ubuntu update for busybox
- SUSE update for busybox
- SUSE update for busybox
- Multiple vulnerabilities in Siemens RUGGEDCOM and SCALANCE Products
- Multiple vulnerabilities in Siemens SCALANCE W-700 IEEE 802.11ax devices
- SUSE update for busybox
- SUSE update for busybox
- Multiple vulnerabilities in Siemens SIMATIC S7-1500 TM MFP - BIOS
- Multiple vulnerabilities in Siemens Integrated SCALANCE S615 of SINAMICS Medium Voltage products
- openEuler update for busybox
- Gentoo update for BusyBox
- Fedora 34 update for busybox
- Fedora 33 update for busybox
- Multiple vulnerabilities in Dell SmartFabric OS10
- Dell SmartFabric OS10 update for third-party components
- Dell Networking OS10 update for third-party components