Use-after-free in BusyBox - CVE-2021-42385

 

Use-after-free in BusyBox - CVE-2021-42385

Published: December 8, 2021


Vulnerability identifier: #VU58683
CSH Severity: Low
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-42385
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in the "evaluate" function. A remote administrator can execute arbitrary code on the target system.


Affected software

BusyBox
Gentoo Linux
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
openSUSE Leap
Ubuntu
openEuler
Fedora
SIMATIC S7-1500 TM MFP - BIOS
SINAMICS GL150
SINAMICS SL150
SINAMICS PERFECT HARMONY GH180 6SR5
SCALANCE S615
cflinuxfs3
SmartFabric OS10
busybox (Ubuntu package)
busybox-static (Ubuntu package)
busybox-initramfs (Ubuntu package)
busybox
busybox-help
busybox-petitboot
busybox-debuginfo
busybox-debugsource
sys-apps/busybox
busybox-static
busybox-warewulf3
busybox-testsuite
SCALANCE WAM766-1 (EU)
SCALANCE WAM763-1
SCALANCE WAM766-1 (US)
SCALANCE WAM766-1 EEC (EU)
SCALANCE WAM766-1 EEC (US)
SCALANCE WUM763-1
SCALANCE WUM766-1 (EU)
SCALANCE WUM766-1 (US)
SCALANCE M876-4 (EU)
RUGGEDCOM RM1224 LTE(4G) EU
RUGGEDCOM RM1224 LTE(4G) NAM
SCALANCE M804PB
SCALANCE M812-1 ADSL-Router (Annex A)
SCALANCE M812-1 ADSL-Router (Annex B)
SCALANCE M816-1 ADSL-Router (Annex A)
SCALANCE M816-1 ADSL-Router (Annex B)
SCALANCE M826-2 SHDSL-Router
SCALANCE M874-2
SCALANCE M874-3
SCALANCE M876-3 (EVDO)
SCALANCE M876-3 (ROK)
SCALANCE M876-4
SCALANCE M876-4 (NAM)
SCALANCE MUM853-1 (EU)
SCALANCE MUM856-1 (EU)
SCALANCE MUM856-1 (RoW)
SCALANCE S615 EEC

How to mitigate CVE-2021-42385

Install updates from vendor's website.

BusyBox - update to 1.34.0
cflinuxfs3 - update to 0.269.0
busybox (Ubuntu package) - addressed in versions 1:1.27.2-2ubuntu3.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-6ubuntu2.1, 1:1.30.1-6ubuntu3.1
busybox-static (Ubuntu package) - addressed in versions 1:1.27.2-2ubuntu3.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-6ubuntu2.1, 1:1.30.1-6ubuntu3.1
busybox-initramfs (Ubuntu package) - addressed in versions 1:1.27.2-2ubuntu3.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-6ubuntu2.1, 1:1.30.1-6ubuntu3.1
busybox - update to 1.31.1-13
busybox-help - update to 1.31.1-13
busybox-petitboot - update to 1.31.1-13
busybox-debuginfo - update to 1.31.1-13
busybox-debugsource - update to 1.31.1-13
sys-apps/busybox - update to 1.34.0
busybox - addressed in versions 1.34.1-1.fc33, 1.34.1-1.fc34
busybox-static - addressed in versions 1.34.1-4.9.1, 1.35.0-150400.3.3.1
busybox - addressed in versions 1.34.1-4.9.1, 1.35.0-4.3.1, 1.35.0-150400.3.3.1
busybox-warewulf3 - update to 1.35.0-150400.3.3.1
busybox-testsuite - update to 1.35.0-150400.3.3.1
SCALANCE WAM766-1 (EU) - update to 2.0
SCALANCE WAM763-1 - update to 2.0
SCALANCE WAM766-1 (US) - update to 2.0
SCALANCE WAM766-1 EEC (EU) - update to 2.0
SCALANCE WAM766-1 EEC (US) - update to 2.0
SCALANCE WUM763-1 - update to 2.0
SCALANCE WUM766-1 (EU) - update to 2.0
SCALANCE WUM766-1 (US) - update to 2.0
SCALANCE S615 - update to 7.2
SCALANCE M876-4 (EU) - update to 7.2
RUGGEDCOM RM1224 LTE(4G) EU - update to 7.2
RUGGEDCOM RM1224 LTE(4G) NAM - update to 7.2
SCALANCE M804PB - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M826-2 SHDSL-Router - update to 7.2
SCALANCE M874-2 - update to 7.2
SCALANCE M874-3 - update to 7.2
SCALANCE M876-3 (EVDO) - update to 7.2
SCALANCE M876-3 (ROK) - update to 7.2
SCALANCE M876-4 - update to 7.2
SCALANCE M876-4 (NAM) - update to 7.2
SCALANCE MUM853-1 (EU) - update to 7.2
SCALANCE MUM856-1 (EU) - update to 7.2
SCALANCE MUM856-1 (RoW) - update to 7.2
SCALANCE S615 EEC - update to 7.2
SmartFabric OS10 - addressed in versions 10.5.4.15, 10.5.5.14, 10.5.6.9

External References

Related Security Bulletins