CVE-2022-30065: Use After Free
A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-30065?
CVE-2022-30065 is a use-after-free vulnerability in Busybox 1.35-x's awk applet that can lead to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.
Which software versions are affected by CVE-2022-30065?
Busybox version 1.35.0 and Apple macOS Big Sur (up to exclusive version 3.0) are affected by CVE-2022-30065.
What is the severity of CVE-2022-30065?
The severity of CVE-2022-30065 is high with a CVSS score of 7.8.
How can CVE-2022-30065 be exploited?
CVE-2022-30065 can be exploited by processing a crafted awk pattern in the copyvar function of Busybox 1.35-x's awk applet.
Where can I find more information about CVE-2022-30065?
More information about CVE-2022-30065 can be found at the following references: [https://bugs.busybox.net/show_bug.cgi?id=14781](https://bugs.busybox.net/show_bug.cgi?id=14781) and [https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdf](https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdf)