https://seclists.org/oss-sec/2025/q2/85: [EXTERNAL] [oss-security] vulnerabilities in busybox tar and cpio tools
Published Apr 24, 2025
·Updated
Affected Software
1 affected component
Busybox Busybox<1.37.0
Frequently Asked Questions
1
What is the severity of CVE-2025-46394?
CVE-2025-46394 is classified as a high severity vulnerability due to its potential impact on the confidentiality and integrity of the system.
2
How do I fix CVE-2025-46394?
To fix CVE-2025-46394, update to the latest version of Busybox, which addresses the vulnerabilities in the tar and cpio tools.
3
Who is affected by CVE-2025-46394?
CVE-2025-46394 affects users of Busybox versions prior to the patched release that includes fixes for the tar and cpio tools.
4
What are the implications of CVE-2025-46394?
The implications of CVE-2025-46394 include potential unauthorized access and manipulation of files processed by the affected tools in Busybox.
5
Is there a workaround for CVE-2025-46394?
Currently, there are no known effective workarounds for CVE-2025-46394, so updating to a fixed version is recommended.