busybox: patch CVE-2024-58251

Pick patch applied by Debian [1].

I did not find any reference on busybox mailing list that this patch was
submitted. Submitting patch for someone else would be inappropriate,
and busybox is currently known to be very inactive, hence the unwanted
Pending Upstream-Status status.
Also note that the related busybox bugreport [2] is currently not
public, so it is possible that it was submitted there.

[1] https://sources.debian.org/patches/busybox/1:1.37.0-10.1/netstat-sanitize-argv0-for-p-CVE-2024-58251.patch/
[2] https://bugs.busybox.net/show_bug.cgi?id=15922

(From OE-Core rev: 6c0b6e39336686590820dce96913f143a45edadf)

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Chen Qi <Qi.Chen@windriver.com>
(cherry picked from commit 7261144785aa508377c995e52d7e2410a814f00b)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
(cherry picked from commit 8f344d46b96fb16632501749dc39b97aa3e11836)

Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
This commit is contained in:
Peter Marko
2026-08-21 10:22:46 +02:00
committed by Richard Purdie
parent b13a89f19d
commit 260984ba5e
2 changed files with 52 additions and 0 deletions

View File

@@ -0,0 +1,51 @@
From: Valery Ushakov <valery.ushakov@bell-sw.com>
Date: Thu, 21 Aug 2025 12:31:53 +0000
Subject: netstat: CVE-2024-58251 - sanitize argv0 for -p
Bug-Debian: https://bugs.debian.org/1104009
Signed-off-by: Valery Ushakov <valery.ushakov@bell-sw.com>
CVE: CVE-2024-58251
Upstream-Status: Pending
Signed-off-by: Peter Marko <peter.marko@siemens.com>
---
networking/netstat.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/networking/netstat.c b/networking/netstat.c
index 807800a62..d979f6079 100644
--- a/networking/netstat.c
+++ b/networking/netstat.c
@@ -41,6 +41,7 @@
#include "libbb.h"
#include "inet_common.h"
+#include "unicode.h"
//usage:#define netstat_trivial_usage
//usage: "[-"IF_ROUTE("r")"al] [-tuwx] [-en"IF_FEATURE_NETSTAT_WIDE("W")IF_FEATURE_NETSTAT_PRG("p")"]"
@@ -314,9 +315,12 @@ static int FAST_FUNC dir_act(struct recursive_state *state,
return FALSE;
cmdline_buf[n] = '\0';
+ /* don't write process-controlled argv[0] to the user's terminal as-is */
+ const char *argv0base = printable_string(bb_basename(cmdline_buf));
+
/* go through all files in /proc/PID/fd and check whether they are sockets */
strcpy(proc_pid_fname + len - (sizeof("cmdline")-1), "fd");
- pid_slash_progname = concat_path_file(pid, bb_basename(cmdline_buf)); /* "PID/argv0" */
+ pid_slash_progname = concat_path_file(pid, argv0base); /* "PID/argv0" */
n = recursive_action(proc_pid_fname,
ACTION_RECURSE | ACTION_QUIET,
add_to_prg_cache_if_socket,
@@ -686,6 +690,7 @@ int netstat_main(int argc UNUSED_PARAM, char **argv)
unsigned opt;
INIT_G();
+ init_unicode();
/* Option string must match NETSTAT_xxx constants */
opt = getopt32(argv, NETSTAT_OPTS);
--
2.34.1

View File

@@ -67,6 +67,7 @@ SRC_URI = "https://busybox.net/downloads/busybox-${PV}.tar.bz2;name=tarball \
file://CVE-2026-29004-01.patch \
file://CVE-2026-29004-02.patch \
file://CVE-2026-38754.patch \
file://CVE-2024-58251.patch \
"
SRC_URI:append:libc-musl = " file://musl.cfg "
# TODO http://lists.busybox.net/pipermail/busybox/2023-January/090078.html