Use-after-free in BusyBox - CVE-2021-42383
Published: November 28, 2022
Vulnerability details
The vulnerability allows a remote user to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the awk applet. A remote privileged user can pass a specially crafted input to the application, trigger a use-after-free error and execute arbitrary code.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
openSUSE Leap
openEuler
Fedora
SINAMICS PERFECT HARMONY GH180 6SR5
SINAMICS SL150
SINAMICS GL150
SCALANCE S615
SIMATIC S7-1500 TM MFP - BIOS
busybox-debugsource
busybox-debuginfo
busybox-petitboot
busybox-help
busybox
sys-apps/busybox
busybox-static
busybox-testsuite
busybox-warewulf3
SCALANCE WUM763-1
SCALANCE WUM766-1 (US)
SCALANCE WUM766-1 (EU)
SCALANCE WAM766-1 EEC (US)
SCALANCE WAM766-1 EEC (EU)
SCALANCE WAM766-1 (US)
SCALANCE WAM766-1 (EU)
SCALANCE WAM763-1
SCALANCE M816-1 ADSL-Router (Annex B)
SCALANCE M876-3 (EVDO)
SCALANCE M876-3 (ROK)
SCALANCE M876-4
RUGGEDCOM RM1224 LTE(4G) EU
RUGGEDCOM RM1224 LTE(4G) NAM
SCALANCE M804PB
SCALANCE M812-1 ADSL-Router (Annex A)
SCALANCE M812-1 ADSL-Router (Annex B)
SCALANCE M816-1 ADSL-Router (Annex A)
SCALANCE S615 EEC
SCALANCE M826-2 SHDSL-Router
SCALANCE M874-2
SCALANCE M876-4 (EU)
SCALANCE M876-4 (NAM)
SCALANCE M874-3
SCALANCE MUM853-1 (EU)
SCALANCE MUM856-1 (EU)
SCALANCE MUM856-1 (RoW)
How to mitigate CVE-2021-42383
busybox-debugsource - update to 1.31.1-13
busybox-debuginfo - update to 1.31.1-13
busybox-petitboot - update to 1.31.1-13
busybox-help - update to 1.31.1-13
busybox - update to 1.31.1-13
sys-apps/busybox - update to 1.34.0
busybox - addressed in versions 1.34.1-1.fc33, 1.34.1-1.fc34
busybox-static - addressed in versions 1.34.1-4.9.1, 1.35.0-150400.3.3.1
busybox - addressed in versions 1.34.1-4.9.1, 1.35.0-4.3.1, 1.35.0-150400.3.3.1
busybox-testsuite - update to 1.35.0-150400.3.3.1
busybox-warewulf3 - update to 1.35.0-150400.3.3.1
SCALANCE WUM763-1 - update to 2.0
SCALANCE WUM766-1 (US) - update to 2.0
SCALANCE WUM766-1 (EU) - update to 2.0
SCALANCE WAM766-1 EEC (US) - update to 2.0
SCALANCE WAM766-1 EEC (EU) - update to 2.0
SCALANCE WAM766-1 (US) - update to 2.0
SCALANCE WAM766-1 (EU) - update to 2.0
SCALANCE WAM763-1 - update to 2.0
SCALANCE M816-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M876-3 (EVDO) - update to 7.2
SCALANCE M876-3 (ROK) - update to 7.2
SCALANCE M876-4 - update to 7.2
RUGGEDCOM RM1224 LTE(4G) EU - update to 7.2
RUGGEDCOM RM1224 LTE(4G) NAM - update to 7.2
SCALANCE M804PB - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE S615 - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE S615 EEC - update to 7.2
SCALANCE M826-2 SHDSL-Router - update to 7.2
SCALANCE M874-2 - update to 7.2
SCALANCE M876-4 (EU) - update to 7.2
SCALANCE M876-4 (NAM) - update to 7.2
SCALANCE M874-3 - update to 7.2
SCALANCE MUM853-1 (EU) - update to 7.2
SCALANCE MUM856-1 (EU) - update to 7.2
SCALANCE MUM856-1 (RoW) - update to 7.2
External References
- https://jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-claroty-and-jfrog/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6T2TURBYYJGBMQTTN2DSOAIQGP7WCPGV/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UQXGOGWBIYWOIVXJVRKHZR34UMEHQBXS/
- https://security.netapp.com/advisory/ntap-20211223-0002/
Related Security Bulletins
- Multiple vulnerabilities in BusyBox
- SUSE update for busybox
- SUSE update for busybox
- Multiple vulnerabilities in Siemens RUGGEDCOM and SCALANCE Products
- Multiple vulnerabilities in Siemens SCALANCE W-700 IEEE 802.11ax devices
- SUSE update for busybox
- SUSE update for busybox
- Multiple vulnerabilities in Siemens SIMATIC S7-1500 TM MFP - BIOS
- Multiple vulnerabilities in Siemens Integrated SCALANCE S615 of SINAMICS Medium Voltage products
- openEuler update for busybox
- Gentoo update for BusyBox
- Fedora 34 update for busybox
- Fedora 33 update for busybox