File _patchinfo of Package patchinfo.42875

<patchinfo incident="42875">
  <!--generated  with prepare-update from request 402158-->
  <issue tracker="bnc" id="1258163">VUL-0: CVE-2026-26157: busybox: Arbitrary file overwrite and potential code execution via incomplete path sanitization</issue>
  <issue tracker="bnc" id="1258167">VUL-0: CVE-2026-26158: busybox: Arbitrary file modification and privilege escalation via unvalidated tar archive entries</issue>
  <issue tracker="cve" id="2026-26157"/>
  <issue tracker="cve" id="2026-26158"/>
  <category>security</category>
  <rating>important</rating>
  <packager>radolin</packager>
  <summary>Security update for busybox</summary>
  <description>This update for busybox fixes the following issues:

- CVE-2026-26157: Arbitrary file overwrite and potential code execution via incomplete path sanitization (bsc#1258163).
- CVE-2026-26158: Arbitrary file modification and privilege escalation via unvalidated tar archive entries
  (bsc#1258167).
</description>
</patchinfo>
openSUSE Build Service is sponsored by