6.5
CVSSv2

CVE-2021-42386

Published: 15/11/2021 Updated: 07/11/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the nvalloc function

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

busybox busybox

fedoraproject fedora 33

fedoraproject fedora 34

Vendor Advisories

Debian Bug report logs - #999567 busybox: CVE-2021-42373 through CVE-2021-42386 (fixed in 134) Package: busybox; Maintainer for busybox is Debian Install System Team <debian-boot@listsdebianorg>; Source for busybox is src:busybox (PTS, buildd, popcon) Reported by: Diederik de Haas <dididebian@cknoworg> Date: Fri ...
A flaw was found in BusyBox, where it did not properly sanitize while processing a crafted shell command, leading to a denial of service The highest threat from this vulnerability is to system availability (CVE-2021-42376) A flaw was found in BusyBox, where it did not properly sanitize while processing a crafted awk pattern, leading to possible c ...
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the nvalloc function ...
A use-after-free in Busybox's awk applet before version 1340 leads to denial of service and possibly code execution when processing a crafted awk pattern in the nvalloc function ...