Back Linuxsecurity openSUSE Leap 15.5 BusyBox Security Warning
This update for busybox fixes the following issues: * CVE-2023-42363: use-after-free vulnerability in xasprintf function in xfuncs_printf.c (bsc#1217580). * CVE-2023-42364: use-after-free in the awk.c evaluate function (bsc#1217584). * CVE-2023-42365: use-after-free in the awk.c copyvar function (bsc#1217585). * CVE-2025-46394: files in a TAR archive can have their filenames hidden from a listing if terminal escape sequences are used when naming other files included in the archive (bsc#1241661). * CVE-2025-60876: request line incorrectly neutralized mat lead to header injection (bsc#1253245). * CVE-2026-26157: Arbitrary file overwrite and potential code execution via incomplete path sanitization (bsc#1258163). * CVE-2026-26158: Arbitrary file modification and privilege escalation via unvalidated tar archive entries (bsc#1258167). * CVE-2021-42380: Additional fix for use-after-realloc in awk (bsc#1192869).
## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-872=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-872=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-872=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-872=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-872=1
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
zypper in -t patch SUSE-2026-872=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-872=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-872=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-872=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-872=1
* openSUSE Leap 15.4 (noarch) * busybox-less-1.35.0-150400.4.7.1 * busybox-net-tools-1.35.0-150400.4.7.1 * busybox-sysvinit-tools-1.35.0-150400.4.7.1 * busybox-tftp-1.35.0-150400.4.7.1 * busybox-sh-1.35.0-150400.4.7.1 * busybox-traceroute-1.35.0-150400.4.7.1 * busybox-vi-1.35.0-150400.4.7.1 * busybox-vlan-1.35.0-150400.4.7.1 * busybox-cpio-1.35.0-150400.4.7.1 * busybox-patch-1.35.0-150400.4.7.1 * busybox-tar-1.35.0-150400.4.7.1 * busybox-tunctl-1.35.0-150400.4.7.1 * busybox-ed-1.35.0-150400.4.7.1 * busybox-diffutils-1.35.0-150400.4.7.1 * busybox-time-1.35.0-150400.4.7.1 * busybox-kmod-1.35.0-150400.4.7.1 * busybox-netcat-1.35.0-150400.4.7.1 * busybox-psmisc-1.35.0-150400.4.7.1 * busybox-grep-1.35.0-150400.4.7.1 * busybox-man-1.35.0-150400.4.7.1 * busybox-selinux-tools-1.35.0-150400.4.7.1 * busybox-telnet-1.35.0-150400.4.7.1 * busybox-bind-utils-1.35.0-150400.4.7.1 * Read the Full Advisory
* openSUSE Leap 15.4 (noarch)
* busybox-less-1.35.0-150400.4.7.1
* busybox-net-tools-1.35.0-150400.4.7.1
* busybox-sysvinit-tools-1.35.0-150400.4.7.1
* busybox-tftp-1.35.0-150400.4.7.1
* busybox-sh-1.35.0-150400.4.7.1
* busybox-traceroute-1.35.0-150400.4.7.1
* busybox-vi-1.35.0-150400.4.7.1
* busybox-vlan-1.35.0-150400.4.7.1
* busybox-cpio-1.35.0-150400.4.7.1
* busybox-patch-1.35.0-150400.4.7.1
* busybox-tar-1.35.0-150400.4.7.1
* busybox-tunctl-1.35.0-150400.4.7.1
* busybox-ed-1.35.0-150400.4.7.1
* busybox-diffutils-1.35.0-150400.4.7.1
* busybox-time-1.35.0-150400.4.7.1
* busybox-kmod-1.35.0-150400.4.7.1
* busybox-netcat-1.35.0-150400.4.7.1
* busybox-psmisc-1.35.0-150400.4.7.1
* busybox-grep-1.35.0-150400.4.7.1
* busybox-man-1.35.0-150400.4.7.1
* busybox-selinux-tools-1.35.0-150400.4.7.1
* busybox-telnet-1.35.0-150400.4.7.1
* busybox-bind-utils-1.35.0-150400.4.7.1
* bsc#1192869 * bsc#1217580 * bsc#1217584 * bsc#1217585 * bsc#1241661 * bsc#1253245 * bsc#1258163 * bsc#1258167 ## References: * * * * * * * * * * * * * * * * Read the Full Advisory
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
