REDHAT-BUG-2531354: Medium severity Busybox Busybox vulnerability
A vulnerability exists in the BusyBox TLS server implementation in networking/tls.c. The getclienthello() function reads p[0] (the compression-methods length byte) after consuming the cipher suite list without verifying that len > 0. A crafted ClientHello that ends immediately after the cipher suite list triggers a 1-byte out-of-bounds heap read.
This is a pre-authentication vulnerability. The one-byte OOB read can potentially leak a single byte of adjacent heap memory or cause a crash in memory-safety-hardened builds.
Affected Software
Event History
Frequently Asked Questions
Does an attacker need credentials to exploit this issue?
No. The issue is pre-authentication; an attacker needs to be able to send a crafted TLS ClientHello to the affected BusyBox TLS server.
Which systems are exposed?
Systems using the BusyBox TLS server implementation are exposed if an attacker can reach that server and initiate a TLS handshake.
What is the likely impact of exploitation?
A crafted ClientHello can cause a one-byte out-of-bounds heap read. This may leak a single adjacent heap byte or cause a crash in memory-safety-hardened builds.