PT-2021-5545 · Busybox+5 · Busybox+5

Published

2021-11-15

·

Updated

2026-03-13

·

CVE-2021-42380

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Busybox (affected versions not specified)
Description A use-after-free issue in Busybox's awk applet can lead to denial of service and possibly code execution when processing a crafted awk pattern in the clrvar function. This can be exploited by a remote attacker to execute arbitrary code in the target system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Use After Free

Weakness Enumeration

Related Identifiers

AZL-6347
BDU:2021-06395
CVE-2021-42380
DLA-4019-1
MGASA-2021-0533
OESA-2021-1449
OPENSUSE-SU-2022:0135-1
OPENSUSE-SU-2022_0135-1
OPENSUSE-SU-2022_3959-1
SUSE-SU-2022:0135-1
SUSE-SU-2022:0135-2
SUSE-SU-2022:3959-1
SUSE-SU-2022:4253-1
SUSE-SU-2026:0872-1
SUSE-SU-2026:0892-1
USN-5179-1

Affected Products

Astra Linux
Busybox
Linuxmint
Red Os
Suse
Ubuntu