CVE Vulnerabilities

CVE-2021-28831

Improper Handling of Exceptional Conditions

Published: Mar 19, 2021 | Modified: Dec 17, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data.

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

NameVendorStart VersionEnd Version
BusyboxBusybox1.32.0 (including)1.32.1 (including)
BusyboxUbuntubionic*
BusyboxUbuntudevel*
BusyboxUbuntuesm-infra-legacy/trusty*
BusyboxUbuntuesm-infra/bionic*
BusyboxUbuntuesm-infra/focal*
BusyboxUbuntuesm-infra/xenial*
BusyboxUbuntufocal*
BusyboxUbuntugroovy*
BusyboxUbuntuhirsute*
BusyboxUbuntuimpish*
BusyboxUbuntujammy*
BusyboxUbuntukinetic*
BusyboxUbuntulunar*
BusyboxUbuntuprecise/esm*
BusyboxUbuntutrusty*
BusyboxUbuntutrusty/esm*
BusyboxUbuntuupstream*
BusyboxUbuntuxenial*

References