buildroot ▾
›
master ▾
›
vulnerability
›
CVE-2022-28391
Component Overview
Vulnerability Overview
Name
CVE-2022-28391
Source
NVD (
link
)
Debian (
link
)
Description
BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.
CWEs
CWE-88
Published Date
Apr 3, 2022
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://git.alpinelinux.org/aports/plain/main/busybox/0001-libbb-sockaddr2str-ensure-only-printable-characters-.patch
Mailing List
https://git.alpinelinux.org/aports/plain/main/busybox/0002-nslookup-sanitize-all-printed-strings-with-printable.patch
Mailing List
https://gitlab.alpinelinux.org/alpine/aports/-/issues/13661
Exploit
https://git.alpinelinux.org/aports/plain/main/busybox/0001-libbb-sockaddr2str-ensure-only-printable-characters-.patch
Mailing List
https://git.alpinelinux.org/aports/plain/main/busybox/0002-nslookup-sanitize-all-printed-strings-with-printable.patch
Mailing List
https://gitlab.alpinelinux.org/alpine/aports/-/issues/13661
Exploit
Analysis
#
Affected Component
Analysis
busybox
Patched
Vulnerability Ratings
#
8.8
CVSSv31
8.8
CVSSv31
6.8
CVSSv2
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
busybox
buildroot
2025.02.x
1.37.0
Patched
busybox
openwrt
master
1.38.0-r2
Not Affected
busybox
openwrt
openwrt-25.12
1.37.0-r6
Not Affected
busybox
yocto
kirkstone
1.35.0
Patched
busybox
yocto
master
1.38.0
Patched
busybox
yocto
scarthgap
1.36.1
Patched
Resolved with patches
#
busybox (buildroot:2025.02.x)
#
Title
Author
Resolve
1
libbb: sockaddr2str: ensure only printable characters are
Ariadne Conill <ariadne@dereferenced.org>
CVE-2022-28391
2
nslookup: sanitize all printed strings with printable_string
Ariadne Conill <ariadne@dereferenced.org>
CVE-2022-28391
busybox (buildroot:master)
#
Title
Author
Resolve
1
libbb: sockaddr2str: ensure only printable characters are
Ariadne Conill <ariadne@dereferenced.org>
CVE-2022-28391
2
nslookup: sanitize all printed strings with printable_string
Ariadne Conill <ariadne@dereferenced.org>
CVE-2022-28391
busybox (yocto:kirkstone)
#
Title
Author
Resolve
1
libbb: sockaddr2str: ensure only printable characters are
Ariadne Conill <ariadne@dereferenced.org>
CVE-2022-28391
2
nslookup: sanitize all printed strings with
Ariadne Conill <ariadne@dereferenced.org>
CVE-2022-28391
busybox (yocto:master)
#
Title
Author
Resolve
1
libbb: sockaddr2str: ensure only printable characters are
Ariadne Conill <ariadne@dereferenced.org>
CVE-2022-28391
2
nslookup: sanitize all printed strings with
Ariadne Conill <ariadne@dereferenced.org>
CVE-2022-28391
busybox (yocto:scarthgap)
#
Title
Author
Resolve
1
libbb: sockaddr2str: ensure only printable characters are
Ariadne Conill <ariadne@dereferenced.org>
CVE-2022-28391
2
nslookup: sanitize all printed strings with
Ariadne Conill <ariadne@dereferenced.org>
CVE-2022-28391