Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Important Patch 2026-0872-1 for openSUSE 15.4 busybox Released Now

suse
Calendar Grey March 12, 2026
Dist Suse Esm H88
Eight vulnerabilities addressed in SUSE's busybox update to ensure system integrity and security. Instant patching recommended.
An update that solves eight vulnerabilities can now be installed.

Summary

## This update for busybox fixes the following issues: * CVE-2023-42363: use-after-free vulnerability in xasprintf function in xfuncs_printf.c (bsc#1217580). * CVE-2023-42364: use-after-free in the awk.c evaluate function (bsc#1217584). * CVE-2023-42365: use-after-free in the awk.c copyvar function (bsc#1217585). * CVE-2025-46394: files in a TAR archive can have their filenames hidden from a listing if terminal escape sequences are used when naming other files included in the archive (bsc#1241661). * CVE-2025-60876: request line incorrectly neutralized mat lead to header injection (bsc#1253245). * CVE-2026-26157: Arbitrary file overwrite and potential code execution via incomplete path sanitization (bsc#1258163). * CVE-2026-26158: Arbitrary file modification and privilege escalation via

References

* bsc#1192869

* bsc#1217580

* bsc#1217584

* bsc#1217585

* bsc#1241661

* bsc#1253245

* bsc#1258163

* bsc#1258167

Cross-

* CVE-2021-42380

* CVE-2023-42363

* CVE-2023-42364

* CVE-2023-42365

* CVE-2025-46394

* CVE-2025-60876

* CVE-2026-26157

* CVE-2026-26158

CVSS scores:

* CVE-2021-42380 ( SUSE ): 6.6 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

* CVE-2021-42380 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

* CVE-2021-42380 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

* CVE-2023-42363 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2023-42363 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2023-42364 ( SUSE ): 5.1

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:0872-1
Release Date: 2026-03-11T17:06:44Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here