package/busybox: patch CVE-2024-58251

Based on the work of the Debian community, this patch fixes the
following vulnerability:

This CVE hasn't been addressed upstream and the bugs discussion is 404
[1]. But the same patch is applied on Busybox v1.38 in Yocto & Debian.

- CVE-2024-58251:
    In netstat in BusyBox through 1.37.0, local users can launch of
    network application with an argv[0] containing an ANSI terminal escape
    sequence, leading to a denial of service (terminal locked up) when
    netstat is used by a victim.

For more information, see:
  - https://salsa.debian.org/installer-team/busybox/-/blob/master/debian/patches/netstat-sanitize-argv0-for-p-CVE-2024-58251.patch
  - https://www.cve.org/CVERecord?id=CVE-2024-58251

This patch is still applied on Debian & Yocto as of busybox version
1.38.

[1] https://bugs.busybox.net/show_bug.cgi?id=15922

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 0e94f8d4de)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
This commit is contained in:
Thomas Perale
2026-08-11 13:35:02 +02:00
committed by Titouan Christophe
parent a5712d326c
commit 7cac2f9a13
2 changed files with 53 additions and 0 deletions

View File

@@ -0,0 +1,50 @@
From: Valery Ushakov <valery.ushakov@bell-sw.com>
Date: Thu, 21 Aug 2025 12:31:53 +0000
Subject: netstat: CVE-2024-58251 - sanitize argv0 for -p
Bug-Debian: https://bugs.debian.org/1104009
Signed-off-by: Valery Ushakov <valery.ushakov@bell-sw.com>
Upstream: https://salsa.debian.org/installer-team/busybox/-/blob/master/debian/patches/netstat-sanitize-argv0-for-p-CVE-2024-58251.patch
CVE: CVE-2024-58251
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
---
networking/netstat.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/networking/netstat.c b/networking/netstat.c
index 807800a62..d979f6079 100644
--- a/networking/netstat.c
+++ b/networking/netstat.c
@@ -41,6 +41,7 @@
#include "libbb.h"
#include "inet_common.h"
+#include "unicode.h"
//usage:#define netstat_trivial_usage
//usage: "[-"IF_ROUTE("r")"al] [-tuwx] [-en"IF_FEATURE_NETSTAT_WIDE("W")IF_FEATURE_NETSTAT_PRG("p")"]"
@@ -314,9 +315,12 @@ static int FAST_FUNC dir_act(struct recursive_state *state,
return FALSE;
cmdline_buf[n] = '\0';
+ /* don't write process-controlled argv[0] to the user's terminal as-is */
+ const char *argv0base = printable_string(bb_basename(cmdline_buf));
+
/* go through all files in /proc/PID/fd and check whether they are sockets */
strcpy(proc_pid_fname + len - (sizeof("cmdline")-1), "fd");
- pid_slash_progname = concat_path_file(pid, bb_basename(cmdline_buf)); /* "PID/argv0" */
+ pid_slash_progname = concat_path_file(pid, argv0base); /* "PID/argv0" */
n = recursive_action(proc_pid_fname,
ACTION_RECURSE | ACTION_QUIET,
add_to_prg_cache_if_socket,
@@ -686,6 +690,7 @@ int netstat_main(int argc UNUSED_PARAM, char **argv)
unsigned opt;
INIT_G();
+ init_unicode();
/* Option string must match NETSTAT_xxx constants */
opt = getopt32(argv, NETSTAT_OPTS);
--
2.34.1

View File

@@ -19,6 +19,9 @@ BUSYBOX_IGNORE_CVES += CVE-2022-28391
# 0007-awk.c-fix-CVE-2023-42366-bug-15874.patch
BUSYBOX_IGNORE_CVES += CVE-2023-42366
# 0012-netstat-sanitize-argv0-for-p-CVE-2024-58251.patch
BUSYBOX_IGNORE_CVES += CVE-2024-58251
# 0010-testsuite-tar-tests-fix-test-after-cve-2025-46394.patch
BUSYBOX_IGNORE_CVES += CVE-2025-46394