Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2022-48174: Busybox Arbitrary Code Execution in IoT Environments

CVE-2022-48174 · published 3 years ago
Summary

A critical vulnerability in Busybox allows attackers to execute arbitrary code on devices, potentially compromising the security of Internet of Vehicles systems. This could lead to unauthorized access, data theft, or system disruption. Update to Busybox 1.35 or later to mitigate this risk.

What to do
  • Update debian busybox to version 1:1.30.1-6+deb11u1.
  • Update debian busybox to version 1:1.35.0-4+deb12u1.
  • Update debian busybox to version 1:1.37.0-1.
  • Update alpine busybox to version 1.36.1-r2.
  • Update alpine busybox to version 1.36.1-r1.
  • Update alpine busybox to version 1.35.0-r310071.
  • Update alpine rootio-busybox to version 1.35.0-r310071.
  • Update alpine busybox to version 1.34.1-r70071.
  • Update alpine rootio-busybox to version 1.34.1-r70071.
Affected software
Ecosystem VendorProductAffected versions
Debian:11 debian busybox < 1:1.30.1-6+deb11u1
Fix: upgrade to 1:1.30.1-6+deb11u1
Debian:12 debian busybox < 1:1.35.0-4+deb12u1
Fix: upgrade to 1:1.35.0-4+deb12u1
Debian:13 debian busybox < 1:1.37.0-1
Fix: upgrade to 1:1.37.0-1
Debian:14 debian busybox < 1:1.37.0-1
Fix: upgrade to 1:1.37.0-1
Alpine:v3.19 alpine busybox < 1.36.1-r2
Fix: upgrade to 1.36.1-r2
Alpine:v3.20 alpine busybox < 1.36.1-r2
Fix: upgrade to 1.36.1-r2
Alpine:v3.21 alpine busybox < 1.36.1-r2
Fix: upgrade to 1.36.1-r2
Alpine:v3.22 alpine busybox < 1.36.1-r2
Fix: upgrade to 1.36.1-r2
Alpine:v3.23 alpine busybox < 1.36.1-r2
Fix: upgrade to 1.36.1-r2
Alpine:v3.24 alpine busybox < 1.36.1-r2
Fix: upgrade to 1.36.1-r2
Alpine:v3.18 alpine busybox < 1.36.1-r1
Fix: upgrade to 1.36.1-r1
Root:Alpine:3.17 alpine busybox < 1.35.0-r310071
Fix: upgrade to 1.35.0-r310071
Root:Alpine:3.17 alpine rootio-busybox < 1.35.0-r310071
Fix: upgrade to 1.35.0-r310071
Root:Alpine:3.15 alpine busybox < 1.34.1-r70071
Fix: upgrade to 1.34.1-r70071
Root:Alpine:3.15 alpine rootio-busybox < 1.34.1-r70071
Fix: upgrade to 1.34.1-r70071
Original advisory text
There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.
There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.
Severity
9.8 Critical
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS 3%
Timeline
Published22 Aug 2023
Updated24 Sep 2026
First seen16 May 2026
Track software like this
Free during beta