Skip to content
openSUSE Leap 15.5 BusyBox Security Warning

openSUSE Leap 15.5 BusyBox Security Warning

Linuxsecurity LinuxSecurity Advisories March 12, 2026

This update for busybox fixes the following issues: * CVE-2023-42363: use-after-free vulnerability in xasprintf function in xfuncs_printf.c (bsc#1217580). * CVE-2023-42364: use-after-free in the awk.c evaluate function (bsc#1217584). * CVE-2023-42365: use-after-free in the awk.c copyvar function (bsc#1217585). * CVE-2025-46394: files in a TAR archive can have their filenames hidden from a listing if terminal escape sequences are used when naming other files included in the archive (bsc#1241661). * CVE-2025-60876: request line incorrectly neutralized mat lead to header injection (bsc#1253245). * CVE-2026-26157: Arbitrary file overwrite and potential code execution via incomplete path sanitization (bsc#1258163). * CVE-2026-26158: Arbitrary file modification and privilege escalation via unvalidated tar archive entries (bsc#1258167). * CVE-2021-42380: Additional fix for use-after-realloc in awk (bsc#1192869).

## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-872=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-872=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-872=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-872=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-872=1

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

zypper in -t patch SUSE-2026-872=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4

zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-872=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4

zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-872=1

* SUSE Linux Enterprise Server 15 SP4 LTSS

zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-872=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP4

zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-872=1

* openSUSE Leap 15.4 (noarch) * busybox-less-1.35.0-150400.4.7.1 * busybox-net-tools-1.35.0-150400.4.7.1 * busybox-sysvinit-tools-1.35.0-150400.4.7.1 * busybox-tftp-1.35.0-150400.4.7.1 * busybox-sh-1.35.0-150400.4.7.1 * busybox-traceroute-1.35.0-150400.4.7.1 * busybox-vi-1.35.0-150400.4.7.1 * busybox-vlan-1.35.0-150400.4.7.1 * busybox-cpio-1.35.0-150400.4.7.1 * busybox-patch-1.35.0-150400.4.7.1 * busybox-tar-1.35.0-150400.4.7.1 * busybox-tunctl-1.35.0-150400.4.7.1 * busybox-ed-1.35.0-150400.4.7.1 * busybox-diffutils-1.35.0-150400.4.7.1 * busybox-time-1.35.0-150400.4.7.1 * busybox-kmod-1.35.0-150400.4.7.1 * busybox-netcat-1.35.0-150400.4.7.1 * busybox-psmisc-1.35.0-150400.4.7.1 * busybox-grep-1.35.0-150400.4.7.1 * busybox-man-1.35.0-150400.4.7.1 * busybox-selinux-tools-1.35.0-150400.4.7.1 * busybox-telnet-1.35.0-150400.4.7.1 * busybox-bind-utils-1.35.0-150400.4.7.1 * Read the Full Advisory

* openSUSE Leap 15.4 (noarch)

* busybox-less-1.35.0-150400.4.7.1

* busybox-net-tools-1.35.0-150400.4.7.1

* busybox-sysvinit-tools-1.35.0-150400.4.7.1

* busybox-tftp-1.35.0-150400.4.7.1

* busybox-sh-1.35.0-150400.4.7.1

* busybox-traceroute-1.35.0-150400.4.7.1

* busybox-vi-1.35.0-150400.4.7.1

* busybox-vlan-1.35.0-150400.4.7.1

* busybox-cpio-1.35.0-150400.4.7.1

* busybox-patch-1.35.0-150400.4.7.1

* busybox-tar-1.35.0-150400.4.7.1

* busybox-tunctl-1.35.0-150400.4.7.1

* busybox-ed-1.35.0-150400.4.7.1

* busybox-diffutils-1.35.0-150400.4.7.1

* busybox-time-1.35.0-150400.4.7.1

* busybox-kmod-1.35.0-150400.4.7.1

* busybox-netcat-1.35.0-150400.4.7.1

* busybox-psmisc-1.35.0-150400.4.7.1

* busybox-grep-1.35.0-150400.4.7.1

* busybox-man-1.35.0-150400.4.7.1

* busybox-selinux-tools-1.35.0-150400.4.7.1

* busybox-telnet-1.35.0-150400.4.7.1

* busybox-bind-utils-1.35.0-150400.4.7.1

* bsc#1192869 * bsc#1217580 * bsc#1217584 * bsc#1217585 * bsc#1241661 * bsc#1253245 * bsc#1258163 * bsc#1258167 ## References: * * * * * * * * * * * * * * * * Read the Full Advisory

*

*

*

*

*

*

*

*

*

*

*

*

*

*

*