Linuxsecurity Critical Vulnerabilities in BusyBox Affecting openSUSE Systems
Article Content
- •Multiple critical vulnerabilities in BusyBox require immediate patching.
- •Arbitrary file overwrite and privilege escalation risks are present in the latest CVEs.
- •Affected systems include openSUSE Leap 15.4 and SUSE Linux Enterprise Server 15 SP4.
A security update for BusyBox addresses multiple vulnerabilities, including CVE-2023-42363, CVE-2023-42364, CVE-2023-42365, CVE-2025-46394, CVE-2025-60876, CVE-2026-26157, and CVE-2026-26158. These vulnerabilities include use-after-free issues and arbitrary file overwrite risks, impacting systems running openSUSE Leap 15.4 and SUSE Linux Enterprise Server 15 SP4. The vulnerabilities could lead to code execution, privilege escalation, and data exposure. Users are advised to apply the patches using recommended installation methods like YaST or zypper. The vulnerabilities were published between 2021 and 2026, with the most recent ones disclosed in February 2026. The update is crucial for maintaining system integrity and security against potential exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2021-42380 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…