PT-2021-2871 · Busybox+4 · Busybox+4
Samuel Sapalski
·
Published
2021-03-03
·
Updated
2025-11-03
·
CVE-2021-28831
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
BusyBox versions 1.32.1 and earlier
Description
The issue is related to the decompress gunzip.c file in BusyBox, which mishandles the error bit on the huft build result pointer. This can lead to an invalid free or segmentation fault when processing malformed gzip data. The vulnerability can be exploited by a remote attacker to cause a denial of service using the gzip compression and decompression utility.
Recommendations
For BusyBox versions 1.32.1 and earlier, update to a version that fixes the issue with the huft build result pointer in decompress gunzip.c.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Handling of Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Busybox
Linuxmint
Suse
Ubuntu