CVE-2021-28831 affecting package busybox for versions less than 1.32.0-2
Details
decompressgunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huftbuild result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data.