summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLivin Sunny <livinsunny519@gmail.com>2026-02-27 16:38:02 -0600
committerRichard Purdie <richard.purdie@linuxfoundation.org>2026-03-16 10:22:06 +0000
commit04ae2d93de5370e495b5c3ae2f2d5748f05c7360 (patch)
tree551eeda0476f1c2c2bbe6e28e40bedb37df4535d
parentda499d6c217a3151a6affb7d56b156e3b7567683 (diff)
downloadpoky-04ae2d93de5370e495b5c3ae2f2d5748f05c7360.tar.gz
busybox: Fixes CVE-2025-60876
This addresses CVE-2025-60876[1], which allows malicious URLs to inject HTTP headers. It has been accepted by Debian[2] and is tracked here [4]. The upstream fix has been submitted [3] and is pending merge. [1] https://nvd.nist.gov/vuln/detail/CVE-2025-60876 [2] https://bugs.debian.org/1120795 [3] https://lists.busybox.net/pipermail/busybox/2025-November/091840.html [4] https://security-tracker.debian.org/tracker/CVE-2025-60876 Upstream-Status: Submitted [https://lists.busybox.net/pipermail/busybox/2025-November/091840.html] (From OE-Core rev: 077f258eb2125359ffe3982c58433ee14cb21f09) Signed-off-by: Livin Sunny <livinsunny519@gmail.com> Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org> (cherry picked from commit f12af98df8f627c6d1836d27be48bac542a4f00e) Signed-off-by: Yoann Congal <yoann.congal@smile.fr> Signed-off-by: Paul Barker <paul@pbarker.dev> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
-rw-r--r--meta/recipes-core/busybox/busybox/CVE-2025-60876.patch42
-rw-r--r--meta/recipes-core/busybox/busybox_1.36.1.bb1
2 files changed, 43 insertions, 0 deletions
diff --git a/meta/recipes-core/busybox/busybox/CVE-2025-60876.patch b/meta/recipes-core/busybox/busybox/CVE-2025-60876.patch
new file mode 100644
index 0000000000..1cf29680e0
--- /dev/null
+++ b/meta/recipes-core/busybox/busybox/CVE-2025-60876.patch
@@ -0,0 +1,42 @@
1From: Radoslav Kolev <radoslav.kolev@suse.com>
2Date: Fri, 21 Nov 2025 11:21:18 +0200
3Subject: wget: don't allow control characters or spaces in the URL
4Bug-Debian: https://bugs.debian.org/1120795
5
6Fixes CVE-2025-60876 malicious URL can be used to inject
7HTTP headers in the request.
8
9Signed-off-by: Radoslav Kolev <radoslav.kolev@suse.com>
10Reviewed-by: Emmanuel Deloget <logout@free.fr>
11
12Upstream-Status: Submitted [https://lists.busybox.net/pipermail/busybox/2025-November/091840.html]
13
14CVE: CVE-2025-60876
15
16Signed-off-by: Livin Sunny <livinsunny519@gmail.com>
17---
18 networking/wget.c | 9 +++++++++
19 1 file changed, 9 insertions(+)
20
21diff --git a/networking/wget.c b/networking/wget.c
22index ec3767793..fa555427b 100644
23--- a/networking/wget.c
24+++ b/networking/wget.c
25@@ -536,6 +536,15 @@ static void parse_url(const char *src_url, struct host_info *h)
26 {
27 char *url, *p, *sp;
28
29+ /* Fix for CVE-2025-60876 - don't allow control characters or spaces in the URL */
30+ /* otherwise a malicious URL can be used to inject HTTP headers in the request */
31+ const unsigned char *u = (void *) src_url;
32+ while (*u) {
33+ if (*u <= ' ')
34+ bb_simple_error_msg_and_die("Unencoded control character found in the URL!");
35+ u++;
36+ }
37+
38 free(h->allocated);
39 h->allocated = url = xstrdup(src_url);
40
41--
422.47.3
diff --git a/meta/recipes-core/busybox/busybox_1.36.1.bb b/meta/recipes-core/busybox/busybox_1.36.1.bb
index d3f259d45b..d870e2ee10 100644
--- a/meta/recipes-core/busybox/busybox_1.36.1.bb
+++ b/meta/recipes-core/busybox/busybox_1.36.1.bb
@@ -61,6 +61,7 @@ SRC_URI = "https://busybox.net/downloads/busybox-${PV}.tar.bz2;name=tarball \
61 file://CVE-2023-39810.patch \ 61 file://CVE-2023-39810.patch \
62 file://CVE-2025-46394-01.patch \ 62 file://CVE-2025-46394-01.patch \
63 file://CVE-2025-46394-02.patch \ 63 file://CVE-2025-46394-02.patch \
64 file://CVE-2025-60876.patch \
64 " 65 "
65SRC_URI:append:libc-musl = " file://musl.cfg " 66SRC_URI:append:libc-musl = " file://musl.cfg "
66# TODO http://lists.busybox.net/pipermail/busybox/2023-January/090078.html 67# TODO http://lists.busybox.net/pipermail/busybox/2023-January/090078.html