Busybox · Busybox · CVE-2021-28831
**Name of the Vulnerable Software and Affected Versions**
BusyBox versions 1.32.1 and earlier
**Description**
The issue is related to the decompress gunzip.c file in BusyBox, which mishandles the error bit on the huft build result pointer. This can lead to an invalid free or segmentation fault when processing malformed gzip data. The vulnerability can be exploited by a remote attacker to cause a denial of service using the gzip compression and decompression utility.
**Recommendations**
For BusyBox versions 1.32.1 and earlier, update to a version that fixes the issue with the huft build result pointer in decompress gunzip.c.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.