CVE-2022-30065

HIGH

Busybox 1.35-x - Use-After-Free in Awk Applet

Title source: llm
STIX 2.1

Description

A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.

References (2)

Core 2
Core References
Exploit, Issue Tracking, Third Party Advisory
https://bugs.busybox.net/show_bug.cgi?id=14781

Scores

CVSS v3 7.8
EPSS 0.0066
EPSS Percentile 71.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-416
Status published
Products (7)
busybox/busybox 1.35.0
siemens/scalance_sc622-2c_firmware < 3.0
siemens/scalance_sc626-2c_firmware < 3.0
siemens/scalance_sc632-2c_firmware < 3.0
siemens/scalance_sc636-2c_firmware < 3.0
siemens/scalance_sc642-2c_firmware < 3.0
siemens/scalance_sc646-2c_firmware < 3.0
Published May 18, 2022
Tracked Since Feb 18, 2026