Out-of-bounds write in BusyBox - CVE-2022-48174

 

Out-of-bounds write in BusyBox - CVE-2022-48174

Published: September 4, 2023


Vulnerability identifier: #VU80391
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-48174
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted input ash.c. A remote attacker can send specially crafted data to the application, trigger an out-of-bounds write and execute arbitrary code on the target system.


Affected software

BusyBox
Engineering Lifecycle Management
Amazon Linux AMI
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems)
SUSE Enterprise Storage
Ubuntu
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
openSUSE Leap
openEuler
Loki
Oracle VM Server for x86
Isolation Segment
VMware Tanzu Application Service for VMs
Oracle Communications Cloud Native Core Network Function Cloud Native Environment
busybox-initramfs (Ubuntu package)
busybox-static (Ubuntu package)
busybox (Ubuntu package)
busybox (Red Hat package)
busybox-debugsource
busybox
busybox-debuginfo
busybox-help
busybox-petitboot
busybox-static
busybox-testsuite
busybox-warewulf3
busybox-vlan
busybox-selinux-tools
busybox-time
busybox-iproute2
busybox-policycoreutils
busybox-wget
busybox-attr
busybox-vi
busybox-tftp
busybox-kmod
busybox-diffutils
busybox-gawk
busybox-kbd
busybox-iputils
busybox-ncurses-utils
busybox-adduser
busybox-tar
busybox-traceroute
busybox-ed
busybox-procps
busybox-psmisc
busybox-unzip
busybox-syslogd
busybox-telnet
busybox-cpio
busybox-sharutils
busybox-bzip2
busybox-sed
busybox-which
busybox-net-tools
busybox-whois
busybox-misc
busybox-less
busybox-xz
busybox-util-linux
busybox-sysvinit-tools
busybox-man
busybox-findutils
busybox-bind-utils
busybox-netcat
busybox-tunctl
busybox-patch
busybox-sh
busybox-coreutils
busybox-bc
busybox-grep
busybox-sendmail
busybox-hostname
busybox-dos2unix
busybox-gzip
busybox-links
rhel-- (Red Hat package)
VMware Tanzu Operations Manager
SmartFabric OS10

How to mitigate CVE-2022-48174

Install updates from vendor's website.

BusyBox - update to 1.35.0
Engineering Lifecycle Management - update to 1.3.0
Loki - addressed in versions 2.8.5, 2.9.1
busybox-initramfs (Ubuntu package) - addressed in versions Ubuntu Pro, 1:1.30.1-4ubuntu6.5, 1:1.30.1-7ubuntu3.1, 1:1.36.1-6ubuntu3.1, 1:1.36.1-6ubuntu4
busybox-static (Ubuntu package) - addressed in versions Ubuntu Pro, 1:1.30.1-4ubuntu6.5, 1:1.30.1-7ubuntu3.1, 1:1.36.1-6ubuntu3.1, 1:1.36.1-6ubuntu4
busybox (Ubuntu package) - addressed in versions Ubuntu Pro, 1:1.30.1-4ubuntu6.5, 1:1.30.1-7ubuntu3.1, 1:1.36.1-6ubuntu3.1, 1:1.36.1-6ubuntu4
busybox (Red Hat package) - update to 1.15.1-21.el6_10.1
busybox-debugsource - update to 1.31.1-19
busybox - update to 1.31.1-19
busybox-debuginfo - update to 1.31.1-19
busybox-help - update to 1.31.1-19
busybox-petitboot - update to 1.31.1-19
busybox - update to 1.34.1-1.16
busybox - addressed in versions 1.35.0-4.12.1, 1.35.0-150000.4.20.1, 1.35.0-150400.3.11.1, 1.35.0-150500.10.3.3
busybox-static - addressed in versions 1.35.0-150000.4.20.1, 1.35.0-150400.3.11.1, 1.35.0-150500.10.3.3
busybox-testsuite - addressed in versions 1.35.0-150400.3.11.1, 1.35.0-150500.10.3.3
busybox-warewulf3 - addressed in versions 1.35.0-150400.3.11.1, 1.35.0-150500.10.3.3
busybox-vlan - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-selinux-tools - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-time - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-iproute2 - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-policycoreutils - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-wget - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-attr - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-vi - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-tftp - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-kmod - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-diffutils - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-gawk - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-kbd - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-iputils - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-ncurses-utils - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-adduser - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-tar - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-traceroute - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-ed - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-procps - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-psmisc - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-unzip - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-syslogd - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-telnet - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-cpio - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-sharutils - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-bzip2 - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-sed - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-which - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-net-tools - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-whois - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-misc - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-less - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-xz - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-util-linux - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-sysvinit-tools - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-man - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-findutils - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-bind-utils - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-netcat - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-tunctl - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-patch - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-sh - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-coreutils - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-bc - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-grep - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-sendmail - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-hostname - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-dos2unix - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-gzip - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
busybox-links - addressed in versions 1.35.0-150400.4.5.1, 1.35.0-150500.7.2.3
VMware Tanzu Operations Manager - update to 2.10.61
Isolation Segment - addressed in versions 2.11.40, 2.13.25, 3.0.18, 4.0.10
VMware Tanzu Application Service for VMs - addressed in versions 2.11.46, 2.13.28, 3.0.18, 4.0.10
rhel-- (Red Hat package) - update to 6/x86_64/7399/busybox/1.15.1-21.el6_10.1/src/fd431d51/package">busybox-1.15.1-21.el6_10.1
SmartFabric OS10 - addressed in versions 10.5.4.15, 10.5.5.14, 10.5.6.9

External References

Related Security Bulletins