CVE-2025-46394: Low severity Busybox tar vulnerability
Published Apr 23, 2025
·Updated
In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.
Affected Software
12 affected components
Busybox tar<=1.37.0
F5 BIG-IP Next SPK>=2.0.0<=2.0.1
F5 BIG-IP Next SPK>=1.7.0<=1.9.2
F5 BIG-IP Next CNF>=2.0.0<=2.0.1
F5 BIG-IP Next CNF>=1.1.0<=1.4.1
F5 BIG-IP Next for Kubernetes=2.0.0
Busybox Busybox<=1.37.0
Microsoft azl3 busybox 1.36.1-17
Microsoft cbl2 busybox 1.35.0-14
Microsoft azl3 busybox 1.36.1-15
Microsoft azl3 busybox 1.36.1-18
Microsoft azl3 busybox 1.36.1-14
Event History
Apr 23, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Jul 23, 2025
Advisory Published
via F5·03:41 PM
Data Sourced
via F5·03:41 PM
DescriptionSeverityWeaknessAffected Software
Sep 4, 2025
Data Sourced
via Microsoft·04:04 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·04:04 AM
Affected Software
Updated
via Microsoft·04:04 AM
DescriptionSeverity
Updated
via Microsoft·04:04 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2025-46394?
CVE-2025-46394 is considered a medium severity vulnerability due to its potential to obscure filenames in TAR archives.
2
How do I fix CVE-2025-46394?
To fix CVE-2025-46394, upgrade BusyBox to version 1.38.0 or later.
3
What does CVE-2025-46394 affect?
CVE-2025-46394 affects the 'tar' utility in BusyBox versions up to and including 1.37.0.
4
What type of vulnerability is CVE-2025-46394?
CVE-2025-46394 is a filename disclosure vulnerability that can hide filenames in TAR archives.
5
Can CVE-2025-46394 be exploited remotely?
CVE-2025-46394 is not classified as a remote exploit but can affect local TAR archive listings.