CVE-2023-42364: Use After Free
Published Nov 27, 2023
·Updated
A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function.
Affected Software
7 affected componentsFixes available
debian/busybox<=1:1.30.1-6, <=1:1.35.0-4, <=1:1.36.1-9
Busybox Busybox=1.36.1
Microsoft cbl2 busybox 1.35.0-13
Microsoft cbl2 busybox 1.35.0-11
Microsoft azl3 busybox 1.36.1-12
Microsoft cbl2 busybox 1.35.0-13
Microsoft azl3 busybox 1.36.1-7
Remediation
Event History
Nov 27, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Aug 14, 2024
Data Sourced
via Launchpad·09:47 PM
Description
Sep 15, 2024
Data Sourced
via Ubuntu·09:52 PM
RemedyDescriptionSeverityAffected Software
Sep 4, 2025
Data Sourced
via Microsoft·06:14 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·06:14 AM
Affected Software
Updated
via Microsoft·06:14 AM
Affected Software
Updated
via Microsoft·06:14 AM
SeverityAffected Software
Updated
via Microsoft·06:14 AM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2023-42364?
CVE-2023-42364 is a use-after-free vulnerability in BusyBox v.1.36.1 that allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function.
2
How can this vulnerability be exploited?
This vulnerability can be exploited by using a crafted awk pattern in the evaluate function of the awk.c file in BusyBox v.1.36.1.
3
What is the severity of CVE-2023-42364?
CVE-2023-42364 has a severity rating of medium.
4
What software versions are affected by CVE-2023-42364?
CVE-2023-42364 affects BusyBox v.1.36.1.
5
Is there a fix available for CVE-2023-42364?
At the moment, there is no known fix available for CVE-2023-42364. It is recommended to update to a version of BusyBox that is not affected by the vulnerability when it becomes available.