PT-2021-2871 · Busybox+4 · Busybox+4

Samuel Sapalski

·

Published

2021-03-03

·

Updated

2025-11-03

·

CVE-2021-28831

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions BusyBox versions 1.32.1 and earlier
Description The issue is related to the decompress gunzip.c file in BusyBox, which mishandles the error bit on the huft build result pointer. This can lead to an invalid free or segmentation fault when processing malformed gzip data. The vulnerability can be exploited by a remote attacker to cause a denial of service using the gzip compression and decompression utility.
Recommendations For BusyBox versions 1.32.1 and earlier, update to a version that fixes the issue with the huft build result pointer in decompress gunzip.c. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Handling of Exceptional Conditions

Weakness Enumeration

Related Identifiers

AZL-6342
BDU:2021-02427
CVE-2021-28831
DLA-2614-1
DLA-4019-1
MGASA-2021-0310
OESA-2021-1162
OPENSUSE-SU-2021:1408-1
OPENSUSE-SU-2021:3531-1
OPENSUSE-SU-2021_1408-1
OPENSUSE-SU-2021_3531-1
OPENSUSE-SU-2022:0135-1
OPENSUSE-SU-2022_0135-1
OPENSUSE-SU-2022_3959-1
OPENSUSE-SU-2024:11738-1
SUSE-SU-2021:3531-1
SUSE-SU-2022:0135-1
SUSE-SU-2022:0135-2
SUSE-SU-2022:3959-1
SUSE-SU-2022:4253-1
USN-5179-1
USN-5179-2
USN-6335-1

Affected Products

Astra Linux
Busybox
Linuxmint
Suse
Ubuntu