CVE-2021-28831: High severity Busybox Busybox vulnerability
decompressgunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huftbuild result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-28831?
CVE-2021-28831 is a vulnerability in BusyBox through version 1.32.1 that mishandles the error bit on the huft_build result pointer, leading to an invalid free or segmentation fault when processing malformed gzip data.
What software is affected by CVE-2021-28831?
BusyBox versions up to and including 1.32.1 are affected by CVE-2021-28831.
How can the CVE-2021-28831 vulnerability be exploited?
The CVE-2021-28831 vulnerability can be exploited by providing the affected software with malformed gzip data, which can trigger an invalid free or segmentation fault.
Is there a fix for CVE-2021-28831?
Yes, updating BusyBox to version 1.32.2 or later will fix the CVE-2021-28831 vulnerability.
Where can I find more information about CVE-2021-28831?
You can find more information about CVE-2021-28831 on the MITRE CVE website and the Ubuntu security notices.