Use-after-free in BusyBox - CVE-2022-30065

 

Use-after-free in BusyBox - CVE-2022-30065

Published: August 8, 2022 / Updated: September 4, 2023


Vulnerability identifier: #VU66182
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-30065
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error when processing a crafted awk pattern in the copyvar function. A remote attacker can execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

BusyBox
Amazon Linux AMI
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
openSUSE Leap
openEuler
SIMATIC S7-1500 TM MFP - BIOS
SCALANCE XCM332
Argo CD
busybox-debugsource
busybox-petitboot
busybox
busybox-debuginfo
busybox-help
busybox-static
busybox-testsuite
busybox-warewulf3
busybox-tftp
busybox-tar
busybox-sysvinit-tools
busybox-syslogd
busybox-sharutils
busybox-sh
busybox-sendmail
busybox-selinux-tools
busybox-sed
busybox-psmisc
busybox-telnet
busybox-procps
busybox-time
busybox-traceroute
busybox-tunctl
busybox-unzip
busybox-util-linux
busybox-vi
busybox-vlan
busybox-wget
busybox-which
busybox-whois
busybox-xz
busybox-patch
busybox-bind-utils
busybox-bc
busybox-attr
busybox-adduser
busybox-bzip2
busybox-coreutils
busybox-cpio
busybox-diffutils
busybox-dos2unix
busybox-ed
busybox-findutils
busybox-gawk
busybox-grep
busybox-gzip
busybox-hostname
busybox-iproute2
busybox-iputils
busybox-policycoreutils
busybox-kbd
busybox-kmod
busybox-less
busybox-links
busybox-man
busybox-misc
busybox-ncurses-utils
busybox-net-tools
busybox-netcat
SCALANCE SC646-2C
SCALANCE SC642-2C
SCALANCE SC636-2C
SCALANCE SC632-2C
SCALANCE SC622-2C
SCALANCE SC626-2C
SCALANCE M876-4 (EU)
SCALANCE S615 EEC
SCALANCE MUM856-1 (RoW)
SCALANCE MUM856-1 (EU)
SCALANCE MUM853-1 (EU)
SCALANCE M876-4 (NAM)
SCALANCE M876-4
SCALANCE M876-3 (ROK)
SCALANCE M876-3 (EVDO)
SCALANCE M874-3
SCALANCE M874-2
SCALANCE M826-2 SHDSL-Router
SCALANCE M816-1 ADSL-Router (Annex B)
SCALANCE M816-1 ADSL-Router (Annex A)
SCALANCE M812-1 ADSL-Router (Annex B)
SCALANCE M812-1 ADSL-Router (Annex A)
SCALANCE M804PB
RUGGEDCOM RM1224 LTE(4G) NAM
RUGGEDCOM RM1224 LTE(4G) EU
SCALANCE S615

How to mitigate CVE-2022-30065

Install update from vendor's website.

Argo CD - addressed in versions 2.2.12, 2.3.7, 2.4.8
busybox-debugsource - update to 1.31.1-15
busybox-petitboot - update to 1.31.1-15
busybox - update to 1.31.1-15
busybox-debuginfo - update to 1.31.1-15
busybox-help - update to 1.31.1-15
busybox - update to 1.34.1-1.15
busybox - addressed in versions 1.35.0-4.6.2, 1.35.0-150000.4.17.1, 1.35.0-150400.3.8.1
busybox-static - addressed in versions 1.35.0-150000.4.17.1, 1.35.0-150400.3.8.1
busybox-testsuite - update to 1.35.0-150400.3.8.1
busybox-warewulf3 - update to 1.35.0-150400.3.8.1
busybox-tftp - update to 1.35.0-150400.4.3.14
busybox-tar - update to 1.35.0-150400.4.3.14
busybox-sysvinit-tools - update to 1.35.0-150400.4.3.14
busybox-syslogd - update to 1.35.0-150400.4.3.14
busybox-sharutils - update to 1.35.0-150400.4.3.14
busybox-sh - update to 1.35.0-150400.4.3.14
busybox-sendmail - update to 1.35.0-150400.4.3.14
busybox-selinux-tools - update to 1.35.0-150400.4.3.14
busybox-sed - update to 1.35.0-150400.4.3.14
busybox-psmisc - update to 1.35.0-150400.4.3.14
busybox-telnet - update to 1.35.0-150400.4.3.14
busybox-procps - update to 1.35.0-150400.4.3.14
busybox-time - update to 1.35.0-150400.4.3.14
busybox-traceroute - update to 1.35.0-150400.4.3.14
busybox-tunctl - update to 1.35.0-150400.4.3.14
busybox-unzip - update to 1.35.0-150400.4.3.14
busybox-util-linux - update to 1.35.0-150400.4.3.14
busybox-vi - update to 1.35.0-150400.4.3.14
busybox-vlan - update to 1.35.0-150400.4.3.14
busybox-wget - update to 1.35.0-150400.4.3.14
busybox-which - update to 1.35.0-150400.4.3.14
busybox-whois - update to 1.35.0-150400.4.3.14
busybox-xz - update to 1.35.0-150400.4.3.14
busybox-patch - update to 1.35.0-150400.4.3.14
busybox-bind-utils - update to 1.35.0-150400.4.3.14
busybox-bc - update to 1.35.0-150400.4.3.14
busybox-attr - update to 1.35.0-150400.4.3.14
busybox-adduser - update to 1.35.0-150400.4.3.14
busybox-bzip2 - update to 1.35.0-150400.4.3.14
busybox-coreutils - update to 1.35.0-150400.4.3.14
busybox-cpio - update to 1.35.0-150400.4.3.14
busybox-diffutils - update to 1.35.0-150400.4.3.14
busybox-dos2unix - update to 1.35.0-150400.4.3.14
busybox-ed - update to 1.35.0-150400.4.3.14
busybox-findutils - update to 1.35.0-150400.4.3.14
busybox-gawk - update to 1.35.0-150400.4.3.14
busybox-grep - update to 1.35.0-150400.4.3.14
busybox-gzip - update to 1.35.0-150400.4.3.14
busybox-hostname - update to 1.35.0-150400.4.3.14
busybox-iproute2 - update to 1.35.0-150400.4.3.14
busybox-iputils - update to 1.35.0-150400.4.3.14
busybox-policycoreutils - update to 1.35.0-150400.4.3.14
busybox-kbd - update to 1.35.0-150400.4.3.14
busybox-kmod - update to 1.35.0-150400.4.3.14
busybox-less - update to 1.35.0-150400.4.3.14
busybox-links - update to 1.35.0-150400.4.3.14
busybox-man - update to 1.35.0-150400.4.3.14
busybox-misc - update to 1.35.0-150400.4.3.14
busybox-ncurses-utils - update to 1.35.0-150400.4.3.14
busybox-net-tools - update to 1.35.0-150400.4.3.14
busybox-netcat - update to 1.35.0-150400.4.3.14
SCALANCE XCM332 - update to 2.2
SCALANCE SC646-2C - update to 3.0
SCALANCE SC642-2C - update to 3.0
SCALANCE SC636-2C - update to 3.0
SCALANCE SC632-2C - update to 3.0
SCALANCE SC622-2C - update to 3.0
SCALANCE SC626-2C - update to 3.0
SCALANCE M876-4 (EU) - update to 7.2
SCALANCE S615 EEC - update to 7.2
SCALANCE S615 - update to 7.2
SCALANCE MUM856-1 (RoW) - update to 7.2
SCALANCE MUM856-1 (EU) - update to 7.2
SCALANCE MUM853-1 (EU) - update to 7.2
SCALANCE M876-4 (NAM) - update to 7.2
SCALANCE M876-4 - update to 7.2
SCALANCE M876-3 (ROK) - update to 7.2
SCALANCE M876-3 (EVDO) - update to 7.2
SCALANCE M874-3 - update to 7.2
SCALANCE M874-2 - update to 7.2
SCALANCE M826-2 SHDSL-Router - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M804PB - update to 7.2
RUGGEDCOM RM1224 LTE(4G) NAM - update to 7.2
RUGGEDCOM RM1224 LTE(4G) EU - update to 7.2

External References

Related Security Bulletins