CVE-2021-42376

Related Vulnerabilities: CVE-2021-42376  

A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare conditions of filtered command input.

Description

The MITRE CVE dictionary describes this issue as:

A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare conditions of filtered command input.

Additional Information

  • Bugzilla 2023891: CVE-2021-42376 busybox: NULL pointer dereference in hush applet leads to denial of service when processing a crafted shell command
  • CWE-476: NULL Pointer Dereference
  • FAQ: Frequently asked questions about CVE-2021-42376