diff options
| author | Livin Sunny <livinsunny519@gmail.com> | 2026-02-27 16:38:02 -0600 |
|---|---|---|
| committer | Richard Purdie <richard.purdie@linuxfoundation.org> | 2026-03-16 10:22:06 +0000 |
| commit | 04ae2d93de5370e495b5c3ae2f2d5748f05c7360 (patch) | |
| tree | 551eeda0476f1c2c2bbe6e28e40bedb37df4535d | |
| parent | da499d6c217a3151a6affb7d56b156e3b7567683 (diff) | |
| download | poky-04ae2d93de5370e495b5c3ae2f2d5748f05c7360.tar.gz | |
busybox: Fixes CVE-2025-60876
This addresses CVE-2025-60876[1], which allows malicious URLs to inject
HTTP headers. It has been accepted by Debian[2] and is tracked here [4].
The upstream fix has been submitted [3] and is pending merge.
[1] https://nvd.nist.gov/vuln/detail/CVE-2025-60876
[2] https://bugs.debian.org/1120795
[3] https://lists.busybox.net/pipermail/busybox/2025-November/091840.html
[4] https://security-tracker.debian.org/tracker/CVE-2025-60876
Upstream-Status: Submitted [https://lists.busybox.net/pipermail/busybox/2025-November/091840.html]
(From OE-Core rev: 077f258eb2125359ffe3982c58433ee14cb21f09)
Signed-off-by: Livin Sunny <livinsunny519@gmail.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit f12af98df8f627c6d1836d27be48bac542a4f00e)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
| -rw-r--r-- | meta/recipes-core/busybox/busybox/CVE-2025-60876.patch | 42 | ||||
| -rw-r--r-- | meta/recipes-core/busybox/busybox_1.36.1.bb | 1 |
2 files changed, 43 insertions, 0 deletions
diff --git a/meta/recipes-core/busybox/busybox/CVE-2025-60876.patch b/meta/recipes-core/busybox/busybox/CVE-2025-60876.patch new file mode 100644 index 0000000000..1cf29680e0 --- /dev/null +++ b/meta/recipes-core/busybox/busybox/CVE-2025-60876.patch | |||
| @@ -0,0 +1,42 @@ | |||
| 1 | From: Radoslav Kolev <radoslav.kolev@suse.com> | ||
| 2 | Date: Fri, 21 Nov 2025 11:21:18 +0200 | ||
| 3 | Subject: wget: don't allow control characters or spaces in the URL | ||
| 4 | Bug-Debian: https://bugs.debian.org/1120795 | ||
| 5 | |||
| 6 | Fixes CVE-2025-60876 malicious URL can be used to inject | ||
| 7 | HTTP headers in the request. | ||
| 8 | |||
| 9 | Signed-off-by: Radoslav Kolev <radoslav.kolev@suse.com> | ||
| 10 | Reviewed-by: Emmanuel Deloget <logout@free.fr> | ||
| 11 | |||
| 12 | Upstream-Status: Submitted [https://lists.busybox.net/pipermail/busybox/2025-November/091840.html] | ||
| 13 | |||
| 14 | CVE: CVE-2025-60876 | ||
| 15 | |||
| 16 | Signed-off-by: Livin Sunny <livinsunny519@gmail.com> | ||
| 17 | --- | ||
| 18 | networking/wget.c | 9 +++++++++ | ||
| 19 | 1 file changed, 9 insertions(+) | ||
| 20 | |||
| 21 | diff --git a/networking/wget.c b/networking/wget.c | ||
| 22 | index ec3767793..fa555427b 100644 | ||
| 23 | --- a/networking/wget.c | ||
| 24 | +++ b/networking/wget.c | ||
| 25 | @@ -536,6 +536,15 @@ static void parse_url(const char *src_url, struct host_info *h) | ||
| 26 | { | ||
| 27 | char *url, *p, *sp; | ||
| 28 | |||
| 29 | + /* Fix for CVE-2025-60876 - don't allow control characters or spaces in the URL */ | ||
| 30 | + /* otherwise a malicious URL can be used to inject HTTP headers in the request */ | ||
| 31 | + const unsigned char *u = (void *) src_url; | ||
| 32 | + while (*u) { | ||
| 33 | + if (*u <= ' ') | ||
| 34 | + bb_simple_error_msg_and_die("Unencoded control character found in the URL!"); | ||
| 35 | + u++; | ||
| 36 | + } | ||
| 37 | + | ||
| 38 | free(h->allocated); | ||
| 39 | h->allocated = url = xstrdup(src_url); | ||
| 40 | |||
| 41 | -- | ||
| 42 | 2.47.3 | ||
diff --git a/meta/recipes-core/busybox/busybox_1.36.1.bb b/meta/recipes-core/busybox/busybox_1.36.1.bb index d3f259d45b..d870e2ee10 100644 --- a/meta/recipes-core/busybox/busybox_1.36.1.bb +++ b/meta/recipes-core/busybox/busybox_1.36.1.bb | |||
| @@ -61,6 +61,7 @@ SRC_URI = "https://busybox.net/downloads/busybox-${PV}.tar.bz2;name=tarball \ | |||
| 61 | file://CVE-2023-39810.patch \ | 61 | file://CVE-2023-39810.patch \ |
| 62 | file://CVE-2025-46394-01.patch \ | 62 | file://CVE-2025-46394-01.patch \ |
| 63 | file://CVE-2025-46394-02.patch \ | 63 | file://CVE-2025-46394-02.patch \ |
| 64 | file://CVE-2025-60876.patch \ | ||
| 64 | " | 65 | " |
| 65 | SRC_URI:append:libc-musl = " file://musl.cfg " | 66 | SRC_URI:append:libc-musl = " file://musl.cfg " |
| 66 | # TODO http://lists.busybox.net/pipermail/busybox/2023-January/090078.html | 67 | # TODO http://lists.busybox.net/pipermail/busybox/2023-January/090078.html |
