CVE-2021-28831
HIGHBusybox < 1.32.1 - Improper Exception Handling
Title source: ruleDescription
decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data.
References (8)
Scores
CVSS v3
7.5
EPSS
0.0102
EPSS Percentile
77.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-755
Status
published
Affected Products (5)
busybox/busybox
< 1.32.1
fedoraproject/fedora
fedoraproject/fedora
fedoraproject/fedora
debian/debian_linux
Timeline
Published
Mar 19, 2021
Tracked Since
Feb 18, 2026