CVE-2021-42376
published 2021-11-15CVE-2021-42376: A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.40%
32.2th percentile
A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare conditions of filtered command input.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| busybox | busybox | >= 0 < 1:1.35.0-1 | 1:1.35.0-1 |
| busybox | busybox | >= 0 < 1:1.35.0-1 | 1:1.35.0-1 |
| busybox | busybox | >= 0 < 1:1.35.0-1 | 1:1.35.0-1 |
| busybox | busybox | >= 1.16.0 < 1.34.0 | 1.34.0 |
| busybox | busybox | >= unspecified < 1.34.0 | 1.34.0 |
| debian | busybox | < busybox 1:1.35.0-1 (bookworm) | busybox 1:1.35.0-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl2_busybox_1.35.0-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_busybox_1.34.1-1_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 TM MFP BIOS
cisa_ics·2023-06-15·CVSS 5.9
[MEDIUM] Siemens SIMATIC S7-1500 TM MFP BIOS
ICS Advisory
##
Siemens SIMATIC S7-1500 TM MFP BIOS
Release DateJune 15, 2023
Alert CodeICSA-23-166-10
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely / low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 TM MFP
- Vulnerabilities: Improper Input Validation, Out-of-bounds Read, Use After Free, Out-of-bounds Write, Infinite Loop, Reachable Assertion, Off-by-one Error, Incorrect Default Permissions, Double Fr
CISA ICS
Siemens SCALANCE Third-Party
cisa_ics·2023-03-21
Siemens SCALANCE Third-Party
ICS Advisory
##
Siemens SCALANCE Third-Party
Release DateMarch 21, 2023
Alert CodeICSA-23-080-07
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.1
- ATTENTION: Exploitable remotely
- Vendor: Siemens
- Equipment: Various third-party components used in SCALANCE W-700 devices
- Vulnerabilities: Generation of Error Message Containing Sensitive Information, Out-of-bounds Write, NULL Pointer Dereference, Out-of-bounds Read, Improper Input Validation, Release of Inval
CISA ICS
Siemens SCALANCE, RUGGEDCOM Third-Party
cisa_ics·2023-03-16
Siemens SCALANCE, RUGGEDCOM Third-Party
ICS Advisory
##
Siemens SCALANCE, RUGGEDCOM Third-Party
Release DateMarch 16, 2023
Alert CodeICSA-23-075-01
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/Low attack complexity
- Vendor: Siemens
- Equipment: Busybox Applet affecting SCALANCE and RUGGEDCOM products
- Vulnerabilities: Out-of-bounds Write, Exposure of Sensitive Information to an Unauthorized Actor, Improper Locking, Improper Input Validation, NULL Pointer Deref
Red Hat
busybox: NULL pointer dereference in hush applet leads to denial of service when processing a crafted shell command
vendor_redhat·2021-11-09·CVSS 5.5
CVE-2021-42376 [MEDIUM] CWE-476 busybox: NULL pointer dereference in hush applet leads to denial of service when processing a crafted shell command
busybox: NULL pointer dereference in hush applet leads to denial of service when processing a crafted shell command
A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare conditions of filtered command input.
A flaw was found in BusyBox, where it did not properly sanitize while processing a crafted shell command, leading to a denial of service. The highest threat from this vulnerability is to system availability.
Package: busybox (Red Hat Enterprise Linux 6) - Not affected
Microsoft
A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command due to missing validation after a \x03 delimiter character. This may be used for
vendor_msrc·2021-11-09·CVSS 5.5
CVE-2021-42376 [MEDIUM] CWE-476 A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command due to missing validation after a \x03 delimiter character. This may be used for
A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare conditions of filtered command input.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact
Debian
CVE-2021-42376: busybox - A NULL pointer dereference in Busybox's hush applet leads to denial of service w...
vendor_debian·2021·CVSS 5.5
CVE-2021-42376 [MEDIUM] CVE-2021-42376: busybox - A NULL pointer dereference in Busybox's hush applet leads to denial of service w...
A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare conditions of filtered command input.
Scope: local
bookworm: resolved (fixed in 1:1.35.0-1)
bullseye: open
forky: resolved (fixed in 1:1.35.0-1)
sid: resolved (fixed in 1:1.35.0-1)
trixie: resolved (fixed in 1:1.35.0-1)
GHSA
GHSA-rxm7-xwcf-84fm: A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation afte
ghsa_unreviewed·2022-05-24
CVE-2021-42376 [HIGH] CWE-476 GHSA-rxm7-xwcf-84fm: A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation afte
A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare conditions of filtered command input.
OSV
CVE-2021-42376: A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation afte
osv·2021-11-15·CVSS 5.5
CVE-2021-42376 [MEDIUM] CVE-2021-42376: A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation afte
A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare conditions of filtered command input.
No detection rules found.
No public exploits indexed.
https://claroty.com/team82/research/unboxing-busybox-14-vulnerabilities-uncovered-by-claroty-jfroghttps://jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-claroty-and-jfrog/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6T2TURBYYJGBMQTTN2DSOAIQGP7WCPGV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UQXGOGWBIYWOIVXJVRKHZR34UMEHQBXS/https://security.netapp.com/advisory/ntap-20211223-0002/https://claroty.com/team82/research/unboxing-busybox-14-vulnerabilities-uncovered-by-claroty-jfroghttps://jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-claroty-and-jfrog/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6T2TURBYYJGBMQTTN2DSOAIQGP7WCPGV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UQXGOGWBIYWOIVXJVRKHZR34UMEHQBXS/https://security.netapp.com/advisory/ntap-20211223-0002/
2021-11-15
Published