From: Thomas Perale via buildroot <buildroot@buildroot.org>
To: buildroot@buildroot.org
Subject: [Buildroot] [PATCH 2025.02.x RESEND 2/5] package/busybox: patch CVE-2024-58251
Date: Tue, 11 Aug 2026 13:42:47 +0200 [thread overview]
Message-ID: <20260811114250.116254-2-thomas.perale@mind.be> (raw)
In-Reply-To: <20260811114250.116254-1-thomas.perale@mind.be>
Based on the work of the Debian community, this patch fixes the
following vulnerability:
- CVE-2024-58251:
In netstat in BusyBox through 1.37.0, local users can launch of
network application with an argv[0] containing an ANSI terminal escape
sequence, leading to a denial of service (terminal locked up) when
netstat is used by a victim.
For more information, see:
- https://salsa.debian.org/installer-team/busybox/-/blob/master/debian/patches/netstat-sanitize-argv0-for-p-CVE-2024-58251.patch
- https://www.cve.org/CVERecord?id=CVE-2024-58251
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
---
...-sanitize-argv0-for-p-CVE-2024-58251.patch | 50 +++++++++++++++++++
package/busybox/busybox.mk | 3 ++
2 files changed, 53 insertions(+)
create mode 100644 package/busybox/0015-netstat-sanitize-argv0-for-p-CVE-2024-58251.patch
diff --git a/package/busybox/0015-netstat-sanitize-argv0-for-p-CVE-2024-58251.patch b/package/busybox/0015-netstat-sanitize-argv0-for-p-CVE-2024-58251.patch
new file mode 100644
index 0000000000..5891424c00
--- /dev/null
+++ b/package/busybox/0015-netstat-sanitize-argv0-for-p-CVE-2024-58251.patch
@@ -0,0 +1,50 @@
+From: Valery Ushakov <valery.ushakov@bell-sw.com>
+Date: Thu, 21 Aug 2025 12:31:53 +0000
+Subject: netstat: CVE-2024-58251 - sanitize argv0 for -p
+Bug-Debian: https://bugs.debian.org/1104009
+
+Signed-off-by: Valery Ushakov <valery.ushakov@bell-sw.com>
+Upstream: https://salsa.debian.org/installer-team/busybox/-/blob/master/debian/patches/netstat-sanitize-argv0-for-p-CVE-2024-58251.patch
+CVE: CVE-2024-58251
+Signed-off-by: Thomas Perale <thomas.perale@mind.be>
+---
+ networking/netstat.c | 7 ++++++-
+ 1 file changed, 6 insertions(+), 1 deletion(-)
+
+diff --git a/networking/netstat.c b/networking/netstat.c
+index 807800a62..d979f6079 100644
+--- a/networking/netstat.c
++++ b/networking/netstat.c
+@@ -41,6 +41,7 @@
+
+ #include "libbb.h"
+ #include "inet_common.h"
++#include "unicode.h"
+
+ //usage:#define netstat_trivial_usage
+ //usage: "[-"IF_ROUTE("r")"al] [-tuwx] [-en"IF_FEATURE_NETSTAT_WIDE("W")IF_FEATURE_NETSTAT_PRG("p")"]"
+@@ -314,9 +315,12 @@ static int FAST_FUNC dir_act(struct recursive_state *state,
+ return FALSE;
+ cmdline_buf[n] = '\0';
+
++ /* don't write process-controlled argv[0] to the user's terminal as-is */
++ const char *argv0base = printable_string(bb_basename(cmdline_buf));
++
+ /* go through all files in /proc/PID/fd and check whether they are sockets */
+ strcpy(proc_pid_fname + len - (sizeof("cmdline")-1), "fd");
+- pid_slash_progname = concat_path_file(pid, bb_basename(cmdline_buf)); /* "PID/argv0" */
++ pid_slash_progname = concat_path_file(pid, argv0base); /* "PID/argv0" */
+ n = recursive_action(proc_pid_fname,
+ ACTION_RECURSE | ACTION_QUIET,
+ add_to_prg_cache_if_socket,
+@@ -686,6 +690,7 @@ int netstat_main(int argc UNUSED_PARAM, char **argv)
+ unsigned opt;
+
+ INIT_G();
++ init_unicode();
+
+ /* Option string must match NETSTAT_xxx constants */
+ opt = getopt32(argv, NETSTAT_OPTS);
+--
+2.34.1
+
diff --git a/package/busybox/busybox.mk b/package/busybox/busybox.mk
index 092fd5d1e1..0488518086 100644
--- a/package/busybox/busybox.mk
+++ b/package/busybox/busybox.mk
@@ -19,6 +19,9 @@ BUSYBOX_IGNORE_CVES += CVE-2022-28391
# 0008-awk.c-fix-CVE-2023-42366-bug-15874.patch
BUSYBOX_IGNORE_CVES += CVE-2023-42366
+# 0015-netstat-sanitize-argv0-for-p-CVE-2024-58251.patch
+BUSYBOX_IGNORE_CVES += CVE-2024-58251
+
# 0012-archival-libarchive-sanitize-filenames-on-output.patch
# 0013-testsuite-tar-tests-fix-test-after-cve-2025-46394.patch
BUSYBOX_IGNORE_CVES += CVE-2025-46394
--
2.55.0
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot
next prev parent reply other threads:[~2026-08-11 11:43 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-11 11:42 [Buildroot] [PATCH 2025.02.x RESEND 1/5] package/busybox: re-introduce IGNORE_CVES for CVE-2023-42366 Thomas Perale via buildroot
2026-08-11 11:42 ` Thomas Perale via buildroot [this message]
2026-08-11 11:42 ` [Buildroot] [PATCH 2025.02.x RESEND 3/5] package/busybox: patch CVE-2023-39810 Thomas Perale via buildroot
2026-08-11 11:42 ` [Buildroot] [PATCH 2025.02.x RESEND 4/5] package/busybox: patch CVE-2026-2615{7, 8} Thomas Perale via buildroot
2026-08-11 11:42 ` [Buildroot] [PATCH 2025.02.x RESEND 5/5] package/busybox: patch CVE-2026-29004 Thomas Perale via buildroot
2026-08-22 12:07 ` [Buildroot] [PATCH 2025.02.x RESEND 1/5] package/busybox: re-introduce IGNORE_CVES for CVE-2023-42366 Titouan Christophe via buildroot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260811114250.116254-2-thomas.perale@mind.be \
--to=buildroot@buildroot.org \
--cc=thomas.perale@mind.be \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox