CVE-2021-42385: Use After Free
Published Nov 15, 2021
·Updated
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function
Affected Software
4 affected componentsFixes available
debian/busybox<=1:1.30.1-6
1:1.35.0-41:1.36.1-9
Busybox Busybox>=1.16.0<=1.33.1
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Event History
Nov 15, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Jan 12, 2024
Data Sourced
via Launchpad·12:01 AM
Description
Sep 15, 2024
Data Sourced
via Ubuntu·09:55 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this use-after-free vulnerability?
The vulnerability ID for this use-after-free vulnerability is CVE-2021-42385.
2
What is the affected software for this vulnerability?
The affected software for this vulnerability is Busybox.
3
What is the severity of CVE-2021-42385?
The severity of CVE-2021-42385 is not specified.
4
How does the use-after-free vulnerability in Busybox's awk applet lead to denial of service?
The use-after-free vulnerability in Busybox's awk applet can lead to denial of service by causing the applet to crash or become unresponsive.
5
Is there a fix available for CVE-2021-42385?
Yes, there are available fixes for CVE-2021-42385 depending on the version of Busybox being used.