CVE-2021-42382: Use After Free
Published Nov 15, 2021
·Updated
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvars function
Affected Software
4 affected componentsFixes available
debian/busybox<=1:1.30.1-6
1:1.35.0-41:1.36.1-9
Busybox Busybox>=1.26.0<=1.33.1
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Event History
Nov 15, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Jan 12, 2024
Data Sourced
via Launchpad·12:01 AM
Description
Sep 15, 2024
Data Sourced
via Ubuntu·09:55 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-42382.
2
What is the title of the vulnerability?
The title of the vulnerability is 'A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_s function.'
3
What is the affected software?
The affected software is Busybox versions 1:1.27.2-2ubuntu3.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-6ubuntu2.1, 1:1.30.1-6ubuntu3.1, 1:1.30.1-7ubuntu2, 1.34.0, and Debian versions 1:1.30.1-4 to 1:1.30.1-6.
4
What is the severity of the vulnerability?
The severity of the vulnerability has not been specified.
5
Is there a fix available for the vulnerability?
Yes, there are fix remedies available for the affected software versions.