### [CVE-2021-42380](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42380) ![](https://img.shields.io/static/v1?label=Product&message=busybox&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=unspecified%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-416&color=brightgreen) ### Description A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the clrvar function ### POC #### Reference - https://claroty.com/team82/research/unboxing-busybox-14-vulnerabilities-uncovered-by-claroty-jfrog - https://jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-claroty-and-jfrog/ #### Github - https://github.com/ChrisAdkin8/Nomad-Job-Vulnerability-Tagging - https://github.com/isgo-golgo13/gokit-gorillakit-enginesvc