{"id":"USN-6961-1","summary":"busybox vulnerabilities","details":"It was discovered that BusyBox did not properly validate user input when\nperforming certain arithmetic operations. If a user or automated system\nwere tricked into processing a specially crafted file, an attacker could\npossibly use this issue to cause a denial of service, or execute arbitrary\ncode. (CVE-2022-48174)\n\nIt was discovered that BusyBox incorrectly managed memory when evaluating\ncertain awk expressions. An attacker could possibly use this issue to cause\na denial of service, or execute arbitrary code. This issue only affected\nUbuntu 24.04 LTS. (CVE-2023-42363, CVE-2023-42364, CVE-2023-42365)\n","modified":"2026-04-27T17:24:52.271075Z","published":"2024-08-14T18:58:35Z","related":["UBUNTU-CVE-2022-48174","UBUNTU-CVE-2023-42363","UBUNTU-CVE-2023-42364","UBUNTU-CVE-2023-42365"],"upstream":["CVE-2022-48174","CVE-2023-42363","CVE-2023-42364","CVE-2023-42365","UBUNTU-CVE-2022-48174","UBUNTU-CVE-2023-42363","UBUNTU-CVE-2023-42364","UBUNTU-CVE-2023-42365"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-6961-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-48174"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-42363"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-42364"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-42365"}],"affected":[{"package":{"name":"busybox","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/busybox@1:1.30.1-4ubuntu6.5?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.30.1-4ubuntu6.5"}]}],"versions":["1:1.30.1-4ubuntu4","1:1.30.1-4ubuntu5","1:1.30.1-4ubuntu6","1:1.30.1-4ubuntu6.1","1:1.30.1-4ubuntu6.2","1:1.30.1-4ubuntu6.3","1:1.30.1-4ubuntu6.4"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"busybox","binary_version":"1:1.30.1-4ubuntu6.5"},{"binary_name":"busybox-initramfs","binary_version":"1:1.30.1-4ubuntu6.5"},{"binary_name":"busybox-static","binary_version":"1:1.30.1-4ubuntu6.5"},{"binary_name":"busybox-syslogd","binary_version":"1:1.30.1-4ubuntu6.5"},{"binary_name":"udhcpc","binary_version":"1:1.30.1-4ubuntu6.5"},{"binary_name":"udhcpd","binary_version":"1:1.30.1-4ubuntu6.5"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6961-1.json","cves_map":{"cves":[{"id":"CVE-2022-48174","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"score":"low","type":"Ubuntu"}]}],"ecosystem":"Ubuntu:20.04:LTS"}}},{"package":{"name":"busybox","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/busybox@1:1.30.1-7ubuntu3.1?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.30.1-7ubuntu3.1"}]}],"versions":["1:1.30.1-6ubuntu3","1:1.30.1-7ubuntu1","1:1.30.1-7ubuntu2","1:1.30.1-7ubuntu3"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"busybox","binary_version":"1:1.30.1-7ubuntu3.1"},{"binary_name":"busybox-initramfs","binary_version":"1:1.30.1-7ubuntu3.1"},{"binary_name":"busybox-static","binary_version":"1:1.30.1-7ubuntu3.1"},{"binary_version":"1:1.30.1-7ubuntu3.1","binary_name":"busybox-syslogd"},{"binary_name":"udhcpc","binary_version":"1:1.30.1-7ubuntu3.1"},{"binary_name":"udhcpd","binary_version":"1:1.30.1-7ubuntu3.1"}]},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2022-48174","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"low","type":"Ubuntu"}]}],"ecosystem":"Ubuntu:22.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6961-1.json"}},{"package":{"name":"busybox","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/busybox@1:1.36.1-6ubuntu3.1?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.36.1-6ubuntu3.1"}]}],"versions":["1:1.36.1-3ubuntu1","1:1.36.1-6ubuntu1","1:1.36.1-6ubuntu3"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"busybox","binary_version":"1:1.36.1-6ubuntu3.1"},{"binary_name":"busybox-initramfs","binary_version":"1:1.36.1-6ubuntu3.1"},{"binary_name":"busybox-static","binary_version":"1:1.36.1-6ubuntu3.1"},{"binary_name":"busybox-syslogd","binary_version":"1:1.36.1-6ubuntu3.1"},{"binary_name":"udhcpc","binary_version":"1:1.36.1-6ubuntu3.1"},{"binary_name":"udhcpd","binary_version":"1:1.36.1-6ubuntu3.1"}]},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2022-48174","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"low","type":"Ubuntu"}]},{"id":"CVE-2023-42363","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2023-42364","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2023-42365"}],"ecosystem":"Ubuntu:24.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6961-1.json"}}],"schema_version":"1.7.5"}