REDHAT-BUG-2531345: High severity Busybox Busybox vulnerability
A vulnerability was found in the BusyBox romfs filesystem volume identification module (util-linux/volumeid/romfs.c). When parsing a romfs superblock, the code calls strlen() on attacker-controlled volume name metadata without any bounds checking. The resulting length is passed to memcpy() via volumeidsetlabelstring(), which copies the data into a fixed-size label field of approximately 65 bytes.
A crafted romfs filesystem image can contain a volume name of up to approximately 4080 bytes. When such an image is processed by blkid or findfs, the unbounded memcpy() writes far beyond the label buffer boundary, corrupting adjacent heap memory.
Affected Software
Event History
Frequently Asked Questions
Which systems and workflows are exposed?
Systems that use the BusyBox romfs volume identification module and process romfs filesystem images with blkid or findfs are exposed to the vulnerable parsing path.
What does an attacker need to exploit this issue?
An attacker needs to provide a crafted romfs filesystem image containing an oversized volume name and cause it to be processed by blkid or findfs. The crafted name can be approximately 4080 bytes, while the destination label field is approximately 65 bytes.
What is the immediate effect of successful exploitation?
Processing the malicious image causes an unbounded copy beyond the fixed-size label buffer, corrupting adjacent heap memory.