安全公告详情

NS-SA-2026-0087

2026-09-07 18:00:00

简介

important: busybox/libxml2 security update

严重级别

important

主题

An update for busybox/libxml2 is now available for NewStart CGSL MAIN 7.02.
NewStart Security has rated this update as having a security impact of important. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

busybox:
libxml2:


Security Fix(es):
busybox: A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159.(CVE-2023-42366)
busybox: A flaw was found in BusyBox wget. This vulnerability allows header injection via raw CR/LF and other C0 control bytes in the HTTP request-target. An attacker can exploit this by crafting a URL containing these control characters to inject arbitrary HTTP headers into the outgoing request, potentially leading to HTTP response splitting, cache poisoning, or security policy bypass.(CVE-2025-60876)
busybox: An escape sequence injection attack was found in BusyBox on Alpine. For this issue to occur, a remote host's virtual terminal must contain an escape sequence, and the victim must then execute netstat. This flaw allows an attacker can inject arbitrary code, leading to a loss of integrity.(CVE-2022-28391)
busybox: In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.(CVE-2025-46394)
busybox: bugfix
libxml2: A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.(CVE-2025-7425)
libxml2: A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors.(CVE-2025-49794)
libxml2: A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.(CVE-2025-6021)
libxml2: A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory.(CVE-2025-49796)
libxml2: A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications.(CVE-2026-0990)
libxml2: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 7.02.07B5.

影响组件

  • busybox
  • libxml2

影响产品

  • CGSL MAIN 7.02

更新包

{"fix":[{"product":"CGSL MAIN 7.02","pkgs":[{"binary":["busybox-shared-1.36.0-2.zncgsl7.40.x86_64.rpm","busybox-core-1.36.0-2.zncgsl7.40.x86_64.rpm","busybox-petitboot-1.36.0-2.zncgsl7.40.x86_64.rpm","busybox-1.36.0-2.zncgsl7.40.x86_64.rpm","busybox-doc-1.36.0-2.zncgsl7.40.noarch.rpm"],"source":"busybox-1.36.0-2.zncgsl7.40.src.rpm"},{"binary":["python3-libxml2-2.11.5-2.zncgsl7.14.x86_64.rpm","libxml2-devel-2.11.5-2.zncgsl7.14.x86_64.rpm","libxml2-core-2.11.5-2.zncgsl7.14.x86_64.rpm","libxml2-doc-2.11.5-2.zncgsl7.14.noarch.rpm","libxml2-static-2.11.5-2.zncgsl7.14.x86_64.rpm","libxml2-2.11.5-2.zncgsl7.14.x86_64.rpm"],"source":"libxml2-2.11.5-2.zncgsl7.14.src.rpm"}]}]}

CVE

参考