CVE-2021-28831

ADVISORY - nist

Summary

decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data.

EPSS Score: 0.01019 (0.768)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Improper Handling of Exceptional Conditions

ADVISORY - redhat

Release of Invalid Pointer or Reference


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in