Impact
BusyBox’s dpkg write_status_file routine fails to reset a cursor between package stanzas, which can cause out‑of‑bounds reads when multiple packages are removed. The resulting corruption of the package status file can lead to package manager inconsistencies, potential loss of service or inadvertent package removal, and in some cases misreporting of system state. The vulnerability does not directly disclose sensitive data but can compromise integrity and availability of package management functions.
Affected Systems
The flaw resides in the dpkg component of BusyBox. No specific version range is given, so any BusyBox installation that includes the vulnerable dpkg implementation may be affected. System administrators should verify which BusyBox versions are in use and whether the installed binary incorporates the fix.
Risk and Exploitability
The CVSS score of 3.3 places this issue in the low‑to‑moderate severity band, and no EPSS estimate is available, indicating that exploitation likelihood is not well characterized. The vulnerability is not listed in the CISA KEV catalog. A local user or process with the ability to trigger removal of several packages can potentially exploit the bug, so the attack vector is likely local. The probable impact is limited to unstable package handling and potential availability disruption rather than immediate remote code execution.
OpenCVE Enrichment