SUSE-SU-2022:3959-1

    Dashboard / Vulnerabilities / SUSE-SU-2022:3959-1

    SUSE-SU-2022:3959-1

    Published: 11 Nov 2022Last Modified: 4 Feb 2026

    Summary: Security update for busybox

    Details: This update for busybox fixes the following issues: - Enable switch_root With this change virtme --force-initramfs works as expected. - Enable udhcpc busybox was updated to 1.35.0 - Adjust busybox.config for new features in find, date and cpio - Annotate CVEs already fixed in upstream, but not mentioned in .changes yet: * CVE-2017-16544 (bsc#1069412): Insufficient sanitization of filenames when autocompleting * CVE-2015-9261 (bsc#1102912): huft_build misuses a pointer, causing segfaults * CVE-2016-2147 (bsc#970663): out of bounds write (heap) due to integer underflow in udhcpc * CVE-2016-2148 (bsc#970662): heap-based buffer overflow in OPTION_6RD parsing * CVE-2016-6301 (bsc#991940): NTP server denial of service flaw * CVE-2017-15873 (bsc#1064976): The get_next_block function in archival/libarchive/decompress_bunzip2.c has an Integer Overflow * CVE-2017-15874 (bsc#1064978): archival/libarchive/decompress_unlzma.c has an Integer Underflow * CVE-2019-5747 (bsc#1121428): out of bounds read in udhcp components * CVE-2021-42373, CVE-2021-42374, CVE-2021-42375, CVE-2021-42376, CVE-2021-42377, CVE-2021-42378, CVE-2021-42379, CVE-2021-42380, CVE-2021-42381, CVE-2021-42382, CVE-2021-42383, CVE-2021-42384, CVE-2021-42385, CVE-2021-42386 (bsc#1192869) : v1.34.0 bugfixes * CVE-2021-28831 (bsc#1184522): invalid free or segmentation fault via malformed gzip data * CVE-2018-20679 (bsc#1121426): out of bounds read in udhcp * CVE-2018-1000517 (bsc#1099260): Heap-based buffer overflow in the retrieve_file_data() * CVE-2011-5325 (bsc#951562): tar directory traversal * CVE-2018-1000500 (bsc#1099263): wget: Missing SSL certificate validation

    References: https://www.suse.com/support/update/announcement/2022/suse-su-20223959-1/, https://bugzilla.suse.com/1064976, https://bugzilla.suse.com/1064978, https://bugzilla.suse.com/1069412, https://bugzilla.suse.com/1099260, https://bugzilla.suse.com/1099263, https://bugzilla.suse.com/1102912, https://bugzilla.suse.com/1121426, https://bugzilla.suse.com/1121428, https://bugzilla.suse.com/1184522, https://bugzilla.suse.com/1192869, https://bugzilla.suse.com/951562, https://bugzilla.suse.com/970662, https://bugzilla.suse.com/970663, https://bugzilla.suse.com/991940, https://www.suse.com/security/cve/CVE-2011-5325, https://www.suse.com/security/cve/CVE-2015-9261, https://www.suse.com/security/cve/CVE-2016-2147, https://www.suse.com/security/cve/CVE-2016-2148, https://www.suse.com/security/cve/CVE-2016-6301, https://www.suse.com/security/cve/CVE-2017-15873, https://www.suse.com/security/cve/CVE-2017-15874, https://www.suse.com/security/cve/CVE-2017-16544, https://www.suse.com/security/cve/CVE-2018-1000500, https://www.suse.com/security/cve/CVE-2018-1000517, https://www.suse.com/security/cve/CVE-2018-20679, https://www.suse.com/security/cve/CVE-2019-5747, https://www.suse.com/security/cve/CVE-2021-28831, https://www.suse.com/security/cve/CVE-2021-42373, https://www.suse.com/security/cve/CVE-2021-42374, https://www.suse.com/security/cve/CVE-2021-42375, https://www.suse.com/security/cve/CVE-2021-42376, https://www.suse.com/security/cve/CVE-2021-42377, https://www.suse.com/security/cve/CVE-2021-42378, https://www.suse.com/security/cve/CVE-2021-42379, https://www.suse.com/security/cve/CVE-2021-42380, https://www.suse.com/security/cve/CVE-2021-42381, https://www.suse.com/security/cve/CVE-2021-42382, https://www.suse.com/security/cve/CVE-2021-42383, https://www.suse.com/security/cve/CVE-2021-42384, https://www.suse.com/security/cve/CVE-2021-42385, https://www.suse.com/security/cve/CVE-2021-42386

    Affected packages

    Package

    Name: busybox

    Purl: pkg:rpm/suse/busybox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.35.0-150400.3.3.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High