Back to Database
Status published
High
CVE-2021-28831
decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on...
Vulnerability Description
decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-28831
Credits & Attribution
No credits recorded in the NVD database.
References
- https://git.busybox.net/busybox/commit/?id=f25d254dfd4243698c31a4f3153d4ac72aa9e9bd
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZASBW7QRRLY5V2R44MQ4QQM4CZIDHM2U/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7ZIFKPRR32ZYA3WAA2NXFA3QHHOU6FJ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UDQGJRECXFS5EZVDH2OI45FMO436AC4/
- https://lists.debian.org/debian-lts-announce/2021/04/msg00001.html
- https://security.gentoo.org/glsa/202105-09
More from busybox
View All →CVE-2022-30065
A use-after-free in Busybox 1.35-x's awk applet leads to denial...
Unknown
0
CVE-2022-28391
BusyBox through 1.35.0 allows remote attackers to execute arbitrary code...
Unknown
0
CVE-2021-42386
A use-after-free in Busybox's awk applet leads to denial of...
Unknown
0
CVE-2021-42385
A use-after-free in Busybox's awk applet leads to denial of...
Unknown
0
CVE-2021-42384
A use-after-free in Busybox's awk applet leads to denial of...
Unknown
0
Affected Vendor
busybox
View all reports →Affected Software
busybox, fedora, debian linux
Vulnerable Versions:
1.32.0, 32, 33, 34, 9.0
Timeline
Official Publish:
March 19th, 2021
Last Modified:
December 17th, 2025
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AC:L/AV:N/A:H/C:N/I:N/PR:N/S:U/UI:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.