https://seclists.org/oss-sec/2025/q2/91: vulnerabilities in busybox tar and cpio tools
Published Apr 24, 2025
·Updated
Affected Software
1 affected component
Busybox Busybox
Frequently Asked Questions
1
What is CVE-2025-46394?
CVE-2025-46394 is a vulnerability in the BusyBox tar tool that can lead to unauthorized file overwrites.
2
What impact does CVE-2024-58251 have?
CVE-2024-58251 affects the BusyBox cpio tool, potentially allowing an attacker to manipulate file extraction processes.
3
What is the severity of CVE-2025-46394?
The severity of CVE-2025-46394 is classified as medium, due to its potential to cause data loss.
4
How do I fix CVE-2025-46394?
To fix CVE-2025-46394, update BusyBox to a version that includes the patch for the vulnerability.
5
How can I mitigate CVE-2024-58251?
Mitigation for CVE-2024-58251 includes restricting access to the cpio tool and applying the latest software updates from BusyBox.