CVE-2022-30065
published 2022-05-18CVE-2022-30065: A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar…
PriorityP337high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.18%
64.2th percentile
A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| busybox | busybox | — | — |
| busybox | busybox | >= 0 < 1:1.36.1-1 | 1:1.36.1-1 |
| busybox | busybox | >= 0 < 1:1.36.1-1 | 1:1.36.1-1 |
| debian | busybox | < busybox 1:1.36.1-1 (forky) | busybox 1:1.36.1-1 (forky) |
| msrc | cbl2_busybox_1.35.0-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| siemens | scalance_sc622-2c_firmware | < 3.0 | 3.0 |
| siemens | scalance_sc626-2c_firmware | < 3.0 | 3.0 |
| siemens | scalance_sc632-2c_firmware | < 3.0 | 3.0 |
| siemens | scalance_sc636-2c_firmware | < 3.0 | 3.0 |
| siemens | scalance_sc642-2c_firmware | < 3.0 | 3.0 |
| siemens | scalance_sc646-2c_firmware | < 3.0 | 3.0 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8LOW
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
BusyBox 1.35-x awk Applet copyvar use after free (Bug 14781 / EUVD-2022-35279)
vuldb·2026-05-29·CVSS 7.8
CVE-2022-30065 [HIGH] BusyBox 1.35-x awk Applet copyvar use after free (Bug 14781 / EUVD-2022-35279)
A vulnerability, which was classified as problematic, was found in BusyBox 1.35-x. This issue affects the function copyvar of the component awk Applet. Executing a manipulation can lead to use after free.
The identification of this vulnerability is CVE-2022-30065. The attack needs to be done within the local network. There is no exploit available.
GHSA
GHSA-gq73-rh3m-3php: A use-after-free in Busybox 1
ghsa_unreviewed·2022-05-19
CVE-2022-30065 [HIGH] CWE-416 GHSA-gq73-rh3m-3php: A use-after-free in Busybox 1
A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.
OSV
CVE-2022-30065: A use-after-free in Busybox 1
osv·2022-05-18·CVSS 7.8
CVE-2022-30065 [HIGH] CVE-2022-30065: A use-after-free in Busybox 1
A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.
CISA ICS
Siemens SIMATIC S7-1500 TM MFP BIOS
cisa_ics·2023-06-15·CVSS 5.9
[MEDIUM] Siemens SIMATIC S7-1500 TM MFP BIOS
ICS Advisory
##
Siemens SIMATIC S7-1500 TM MFP BIOS
Release DateJune 15, 2023
Alert CodeICSA-23-166-10
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely / low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 TM MFP
- Vulnerabilities: Improper Input Validation, Out-of-bounds Read, Use After Free, Out-of-bounds Write, Infinite Loop, Reachable Assertion, Off-by-one Error, Incorrect Default Permissions, Double Fr
CISA ICS
Siemens SCALANCE XCM332
cisa_ics·2023-04-13·CVSS 7.5
[HIGH] Siemens SCALANCE XCM332
ICS Advisory
##
Siemens SCALANCE XCM332
Release DateApril 13, 2023
Alert CodeICSA-23-103-09
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM332
- Vulnerabilities: Allocation of Resources Without Limits or Throttling, Use After Free, Concurrent Execution Using Shared Resource with Improper Synchronization ('Race Condition'), Incorrect Default Permissions, Out-of-
CISA ICS
Siemens SCALANCE, RUGGEDCOM Third-Party
cisa_ics·2023-03-16
Siemens SCALANCE, RUGGEDCOM Third-Party
ICS Advisory
##
Siemens SCALANCE, RUGGEDCOM Third-Party
Release DateMarch 16, 2023
Alert CodeICSA-23-075-01
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/Low attack complexity
- Vendor: Siemens
- Equipment: Busybox Applet affecting SCALANCE and RUGGEDCOM products
- Vulnerabilities: Out-of-bounds Write, Exposure of Sensitive Information to an Unauthorized Actor, Improper Locking, Improper Input Validation, NULL Pointer Deref
CISA ICS
Siemens SCALANCE SC-600 Family
cisa_ics·2022-12-15
Siemens SCALANCE SC-600 Family
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE SC-600 Family
Last RevisedDecember 15, 2022
Alert CodeICSA-22-349-18
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE SC-600 Family
- Vulnerability: Out-of-bounds Write, Use After Free, Allocation of Resources Without Limits or Throttling
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow a denial-of-service condition, corrupt memory, or potentially execute custom code.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions
Red Hat
busybox: A use-after-free in Busybox's awk applet leads to denial of service
vendor_redhat·2022-05-18·CVSS 7.8
CVE-2022-30065 [HIGH] CWE-416 busybox: A use-after-free in Busybox's awk applet leads to denial of service
busybox: A use-after-free in Busybox's awk applet leads to denial of service
A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.
A flaw was found in BusyBox. It did not properly sanitize while processing a crafted awk pattern, leading to possible code execution.
Package: busybox (Red Hat Enterprise Linux 6) - Out of support scope
Microsoft
A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.
vendor_msrc·2022-05-10·CVSS 7.8
CVE-2022-30065 [HIGH] CWE-416 A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.
A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mar
Debian
CVE-2022-30065: busybox - A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and p...
vendor_debian·2022·CVSS 7.8
CVE-2022-30065 [HIGH] CVE-2022-30065: busybox - A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and p...
A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:1.36.1-1)
sid: resolved (fixed in 1:1.36.1-1)
trixie: resolved (fixed in 1:1.36.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-05-18
Published