Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2022-48174

Published: August 22, 2023Last modified: August 1, 2025

Description

There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.

Severity score breakdown

ParameterValue
Base score9.8
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Notes

Fix: https://git.busybox.net/busybox/commit/?id=d417193cf37ca1005830d7e16f5fa7e1d8a44209

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSbusyboxFixed (1.35.0-r34)
Hardened Containers23 LTSbusyboxFixed (1.35.0-r34)

References

ON THIS PAGE