CVE-2023-42365
NixOS vulnerability analysis and mitigation

Overview

A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar function. The vulnerability was identified and reported on November 23, 2023, affecting the awk applet component of BusyBox (BusyBox Bug).

Technical details

The vulnerability exists in the copyvar function at line 1064 of awk.c. The issue occurs when processing certain awk patterns that can trigger a use-after-free condition. The vulnerability has been assigned a CVSS 3.1 Base Score of 5.5 (Medium) with the vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, indicating local attack vector, low attack complexity, no privileges required, and high impact on availability (NVD).

Impact

The vulnerability primarily affects system availability, with no direct impact on confidentiality or integrity. When successfully exploited, it can cause the awk component to crash due to memory corruption, potentially leading to denial of service (NVD).

Mitigation and workarounds

The vulnerability has been fixed in BusyBox version 1.37.0 through commit 0256e00a9d077588bd3a39f5a1ef7e2eaa2911e4. However, this fix introduced a regression that was subsequently addressed by commit 38335df9e9f45378c3407defd38b5b610578bdda. Users are advised to upgrade to the fixed version (Debian Tracker).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-12819HIGH8.1
  • NixOSNixOS
  • pgbouncer
NoYesDec 03, 2025
CVE-2025-20777MEDIUM6.7
  • NixOSNixOS
  • android
NoNoDec 02, 2025
CVE-2025-65105MEDIUM5.3
  • NixOSNixOS
  • apptainer
NoYesDec 02, 2025
CVE-2025-20789MEDIUM4.4
  • NixOSNixOS
  • android
NoNoDec 02, 2025
CVE-2025-20788MEDIUM4.4
  • NixOSNixOS
  • android
NoNoDec 02, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management