Skip to content
This repository was archived by the owner on Jan 7, 2026. It is now read-only.

doc(busybox): CVE-2025-60876#28256

Merged
dnegreira merged 1 commit intowolfi-dev:mainfrom
catmsred:busybox/CVE-2025-60876
Jan 7, 2026
Merged

doc(busybox): CVE-2025-60876#28256
dnegreira merged 1 commit intowolfi-dev:mainfrom
catmsred:busybox/CVE-2025-60876

Conversation

@catmsred
Copy link
Member

@catmsred catmsred commented Jan 6, 2026

The vulnerability advisory[1] does not list a fixed version. There
are two patches submitted to the mailing list[2][3] purporting to fix
the vulnerability, but neither has been merged upstream[4] yet.
Upstream busybox maintainers will need to determine the best way and
patch the code base.

[1] GHSA-48hw-cv6f-mcpj
[2] https://lists.busybox.net/pipermail/busybox/2025-August/091710.html
[3] https://lists.busybox.net/pipermail/busybox/2025-November/091818.html
[4] https://git.busybox.net/busybox

Relates: https://github.com/chainguard-dev/CVE-Dashboard/issues/52331

The vulnerability advisory[1] does not list a fixed version. There
are two patches submitted to the mailing list[2][3] purporting to fix
the vulnerability, but neither has been merged upstream[4] yet.
Upstream busybox maintainers will need to determine the best way and
patch the code base.

[1] GHSA-48hw-cv6f-mcpj
[2] https://lists.busybox.net/pipermail/busybox/2025-August/091710.html
[3] https://lists.busybox.net/pipermail/busybox/2025-November/091818.html
[4] https://git.busybox.net/busybox

Relates: chainguard-dev/CVE-Dashboard#52331
@catmsred catmsred marked this pull request as ready for review January 6, 2026 18:48
@catmsred catmsred requested a review from a team January 6, 2026 19:38
@dnegreira dnegreira added this pull request to the merge queue Jan 7, 2026
Merged via the queue into wolfi-dev:main with commit d5ac2be Jan 7, 2026
4 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

Comments