Denial of Service Vulnerability in BusyBox netstat Affected by Terminal Escape Sequences
CVE-2024-58251

2.5LOW

Key Information:

Vendor

Busybox

Status
Vendor
CVE Published:
23 April 2025

What is CVE-2024-58251?

The netstat utility in BusyBox versions up to 1.37.0 is vulnerable to a denial of service issue. Local users can exploit this vulnerability by launching a network application with an argv[0] argument that contains an ANSI terminal escape sequence. This can cause a terminal lock-up when the affected netstat command is executed by a victim, rendering the terminal unusable until it is reset. This issue highlights the potential for localized disruptions within systems running the vulnerable BusyBox version, emphasizing the need for prompt updates and security practices.

Affected Version(s)

BusyBox 0 <= 1.37.0

References

CVSS V3.1

Score:
2.5
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.