CVE-2017-15874: Busybox

Medium severity, CVSS 5.0. EPSS: 0.9% chance of exploitation in the next 30 days.

archival/libarchive/decompress_unlzma.c in BusyBox 1.27.2 has an Integer Underflow that leads to a read access violation.

Affected products

  • Busybox Busybox: version 1.27.2 only

Published 2017-10-24. Last modified 2026-06-17.