CVE-2013-1813: Busybox

High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.

util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows local users to have unknown impact and attack vectors.

Affected products

  • Busybox Busybox: up to and including 1.20.2; version 0.38 only; version 0.39 only; version 0.40 only; version 0.41 only; version 0.42 only; …
  • Red Hat Enterprise Linux: version 6.0 only
  • T-Mobile TM-AC1900: version 3.0.0.4.376_3169 only

Published 2013-11-23. Last modified 2026-06-16.