CVE-2021-42374 affecting package busybox for versions less than 1.35.1-1
Details
An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that