Skip to content

[3.19] main/busybox: backport patch for CVE-2023-42366

Sören Tempel requested to merge nmeum/aports:3.19-CVE-2023-42366 into 3.19-stable

Follow-up for !63398 (merged).

I am still unsure if we want to backport this because:

  1. The CVE is bogus in the sense that this is not a security problem unless you are executing attacker-controlled awk code.
  2. The fix is not upstream, this is just a patch taken from the BusyBox bug tracker.

Furthermore, if we want to backport this we also need to backport it for additional -stable branches.

Edited by Sören Tempel

Merge request reports