Related Vulnerabilities: CVE-2022-30065  

A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.

Description

The MITRE CVE dictionary describes this issue as:

A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.

Additional Information

  • Bugzilla 2088233: CVE-2022-30065 busybox: A use-after-free in Busybox's awk applet leads to denial of service
  • CWE-416: Use After Free
  • FAQ: Frequently asked questions about CVE-2022-30065