{"id":"SUSE-SU-2022:4371-1","summary":"Security update for busybox","details":"This update for busybox fixes the following issues:\n\n- CVE-2022-30065: Fixed use-after-free in the AWK applet (bsc#1199744). \n- CVE-2014-9645: Fixed loading of unwanted module with / in module names (bsc#914660).\n\n- Update to 1.35.0 also introduced:\n  - awk: fix printf %%, fix read beyond end of buffer\n  - chrt: silence analyzer warning\n  - libarchive: remove duplicate forward declaration\n  - mount: 'mount -o rw ....' should not fall back to RO mount\n  - ps: fix -o pid=PID,args interpreting entire 'PID,args' as header\n  - tar: prevent malicious archives with long name sizes causing OOM\n  - udhcpc6: fix udhcp_find_option to actually find DHCP6 options\n  - xxd: fix -p -r\n  - support for new optoins added to basename, cpio, date, find, \n    mktemp, wget and others\n","modified":"2026-03-11T07:21:45.695103Z","published":"2022-12-08T16:19:54Z","related":["CVE-2014-9645","CVE-2022-30065"],"upstream":["CVE-2014-9645","CVE-2022-30065"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20224371-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1199744"},{"type":"REPORT","url":"https://bugzilla.suse.com/914660"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-9645"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-30065"}],"affected":[{"package":{"name":"busybox","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP4","purl":"pkg:rpm/suse/busybox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.35.0-150400.3.8.1"}]}],"ecosystem_specific":{"binaries":[{"busybox-static":"1.35.0-150400.3.8.1","busybox":"1.35.0-150400.3.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:4371-1.json"}},{"package":{"name":"busybox","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/busybox&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.35.0-150400.3.8.1"}]}],"ecosystem_specific":{"binaries":[{"busybox-iputils":"1.35.0-150400.4.3.14","busybox-ncurses-utils":"1.35.0-150400.4.3.14","busybox-tftp":"1.35.0-150400.4.3.14","busybox-traceroute":"1.35.0-150400.4.3.14","busybox-warewulf3":"1.35.0-150400.3.8.1","busybox-wget":"1.35.0-150400.4.3.14","busybox-gzip":"1.35.0-150400.4.3.14","busybox-less":"1.35.0-150400.4.3.14","busybox-links":"1.35.0-150400.4.3.14","busybox-procps":"1.35.0-150400.4.3.14","busybox-selinux-tools":"1.35.0-150400.4.3.14","busybox-tar":"1.35.0-150400.4.3.14","busybox-time":"1.35.0-150400.4.3.14","busybox-vi":"1.35.0-150400.4.3.14","busybox-bind-utils":"1.35.0-150400.4.3.14","busybox-gawk":"1.35.0-150400.4.3.14","busybox-hostname":"1.35.0-150400.4.3.14","busybox-iproute2":"1.35.0-150400.4.3.14","busybox-static":"1.35.0-150400.3.8.1","busybox-vlan":"1.35.0-150400.4.3.14","busybox-whois":"1.35.0-150400.4.3.14","busybox-xz":"1.35.0-150400.4.3.14","busybox-attr":"1.35.0-150400.4.3.14","busybox-misc":"1.35.0-150400.4.3.14","busybox-net-tools":"1.35.0-150400.4.3.14","busybox-psmisc":"1.35.0-150400.4.3.14","busybox-syslogd":"1.35.0-150400.4.3.14","busybox-telnet":"1.35.0-150400.4.3.14","busybox-unzip":"1.35.0-150400.4.3.14","busybox-util-linux":"1.35.0-150400.4.3.14","busybox-bc":"1.35.0-150400.4.3.14","busybox-coreutils":"1.35.0-150400.4.3.14","busybox-kmod":"1.35.0-150400.4.3.14","busybox-man":"1.35.0-150400.4.3.14","busybox-netcat":"1.35.0-150400.4.3.14","busybox-sed":"1.35.0-150400.4.3.14","busybox-sysvinit-tools":"1.35.0-150400.4.3.14","busybox-testsuite":"1.35.0-150400.3.8.1","busybox-bzip2":"1.35.0-150400.4.3.14","busybox-diffutils":"1.35.0-150400.4.3.14","busybox-findutils":"1.35.0-150400.4.3.14","busybox-policycoreutils":"1.35.0-150400.4.3.14","busybox-sharutils":"1.35.0-150400.4.3.14","busybox-sh":"1.35.0-150400.4.3.14","busybox":"1.35.0-150400.3.8.1","busybox-adduser":"1.35.0-150400.4.3.14","busybox-ed":"1.35.0-150400.4.3.14","busybox-grep":"1.35.0-150400.4.3.14","busybox-tunctl":"1.35.0-150400.4.3.14","busybox-which":"1.35.0-150400.4.3.14","busybox-cpio":"1.35.0-150400.4.3.14","busybox-dos2unix":"1.35.0-150400.4.3.14","busybox-kbd":"1.35.0-150400.4.3.14","busybox-patch":"1.35.0-150400.4.3.14","busybox-sendmail":"1.35.0-150400.4.3.14"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:4371-1.json"}},{"package":{"name":"busybox-links","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/busybox-links&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.35.0-150400.4.3.14"}]}],"ecosystem_specific":{"binaries":[{"busybox-gzip":"1.35.0-150400.4.3.14","busybox-psmisc":"1.35.0-150400.4.3.14","busybox-sed":"1.35.0-150400.4.3.14","busybox-wget":"1.35.0-150400.4.3.14","busybox-whois":"1.35.0-150400.4.3.14","busybox-bind-utils":"1.35.0-150400.4.3.14","busybox-netcat":"1.35.0-150400.4.3.14","busybox-policycoreutils":"1.35.0-150400.4.3.14","busybox-unzip":"1.35.0-150400.4.3.14","busybox-vi":"1.35.0-150400.4.3.14","busybox-xz":"1.35.0-150400.4.3.14","busybox":"1.35.0-150400.3.8.1","busybox-attr":"1.35.0-150400.4.3.14","busybox-ed":"1.35.0-150400.4.3.14","busybox-iproute2":"1.35.0-150400.4.3.14","busybox-iputils":"1.35.0-150400.4.3.14","busybox-misc":"1.35.0-150400.4.3.14","busybox-net-tools":"1.35.0-150400.4.3.14","busybox-patch":"1.35.0-150400.4.3.14","busybox-grep":"1.35.0-150400.4.3.14","busybox-sh":"1.35.0-150400.4.3.14","busybox-tar":"1.35.0-150400.4.3.14","busybox-tunctl":"1.35.0-150400.4.3.14","busybox-which":"1.35.0-150400.4.3.14","busybox-coreutils":"1.35.0-150400.4.3.14","busybox-kbd":"1.35.0-150400.4.3.14","busybox-kmod":"1.35.0-150400.4.3.14","busybox-man":"1.35.0-150400.4.3.14","busybox-ncurses-utils":"1.35.0-150400.4.3.14","busybox-time":"1.35.0-150400.4.3.14","busybox-bc":"1.35.0-150400.4.3.14","busybox-diffutils":"1.35.0-150400.4.3.14","busybox-hostname":"1.35.0-150400.4.3.14","busybox-less":"1.35.0-150400.4.3.14","busybox-selinux-tools":"1.35.0-150400.4.3.14","busybox-telnet":"1.35.0-150400.4.3.14","busybox-testsuite":"1.35.0-150400.3.8.1","busybox-util-linux":"1.35.0-150400.4.3.14","busybox-adduser":"1.35.0-150400.4.3.14","busybox-procps":"1.35.0-150400.4.3.14","busybox-sendmail":"1.35.0-150400.4.3.14","busybox-sharutils":"1.35.0-150400.4.3.14","busybox-syslogd":"1.35.0-150400.4.3.14","busybox-tftp":"1.35.0-150400.4.3.14","busybox-traceroute":"1.35.0-150400.4.3.14","busybox-vlan":"1.35.0-150400.4.3.14","busybox-bzip2":"1.35.0-150400.4.3.14","busybox-dos2unix":"1.35.0-150400.4.3.14","busybox-links":"1.35.0-150400.4.3.14","busybox-static":"1.35.0-150400.3.8.1","busybox-sysvinit-tools":"1.35.0-150400.4.3.14","busybox-warewulf3":"1.35.0-150400.3.8.1","busybox-cpio":"1.35.0-150400.4.3.14","busybox-findutils":"1.35.0-150400.4.3.14","busybox-gawk":"1.35.0-150400.4.3.14"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:4371-1.json"}}],"schema_version":"1.7.5"}