Arbitrary file truncation in busybox patch binary
Arthur Chan
arthur.chan at adalogics.com
Mon Apr 13 21:58:58 UTC 2026
Hi,
I am writing to report an arbitrary file truncation in busybox project and specifically in the patch binary when processing a malicious patch file could truncate or create arbitrary file in the file system with the user privilege.
It is triggerable through the `busybox patch` when the system manager or cornjob applys regular patches which include a malicious patch file. It will result in arbitrary file truncation or creation through direct path traversal that may affect important system file with the user privilege.
I have attached a markdown arbitrary_file_truncation.md that holds detail descriptions and reproduction steps of the vulnerability.
This issue was found by Anthropic from using agents to study security of open source projects, and I am from Ada Logics helping validate the found issues and report to maintainers. The data in this email has been reviewed manually.
Please let me know if you have any questions!
Kind regards,
Arthur Chan
ADA Logics Ltd is registered in England. No: 11624074.
Registered office: 266 Banbury Road, Post Box 292,
OX2 7DL, Oxford, Oxfordshire , United Kingdom
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.busybox.net/pipermail/busybox/attachments/20260413/83c09e45/attachment-0001.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: arbitrary_file_truncation.md
Type: text/markdown
Size: 5520 bytes
Desc: not available
URL: <http://lists.busybox.net/pipermail/busybox/attachments/20260413/83c09e45/attachment-0001.md>
More information about the busybox
mailing list