Fedora Account System
Red Hat Associate
Red Hat Customer
A vulnerability was found in the BusyBox dpkg implementation (archival/dpkg.c). The write_status_file() function does not reset the field_start cursor between package stanzas. When two packages are removed in a single invocation and the first stanza is larger than the second, the stale cursor causes an out-of-bounds read and silent corruption of the dpkg status file. Upstream fix commits: f5a4a02a1, d5cc94063. Reporter: Shubham Raj, Causal Security. PSIRT Ticket: PSIRTSUPT-23314.