Updated: 2025-08-20 03:12:17.337224
Description:
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_s function
| Links | NIST | CIRCL | RHEL | Ubuntu |
| Severity | Score | |
|---|---|---|
| CVSS Version 2.x | MEDIUM | 6.5 |
| CVSS Version 3.x | HIGH | 7.2 |
| OS name | Project name | Version | Score | Severity | Status | Errata | Last updated | Statement |
|---|---|---|---|---|---|---|---|---|
| Debian 10 ELS | busybox | 1.30.1 | 7.2 | HIGH | Released | CLSA-2025:1761844489 | 2025-10-31 01:25:43 | |
| Ubuntu 16.04 ELS | busybox | 1.22.0 | 7.2 | HIGH | Released | CLSA-2021:1638804058 | 2022-01-04 14:19:58 | |
| Ubuntu 18.04 ELS | busybox | 1.27.2 | 7.2 | HIGH | Already Fixed | 2023-06-02 09:11:08 |