{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/oraclelinux6els/vex/2025/cve-2025-60876-els_os-oraclelinux6els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-03T13:44:42Z",
      "generator": {
        "date": "2026-08-03T13:44:42Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2025-60876-ELS_OS-ORACLELINUX6ELS",
      "initial_release_date": "2025-11-10T20:15:00Z",
      "revision_history": [
        {
          "date": "2025-11-10T20:15:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-01T22:48:06Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-08-03T13:44:42Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2025-60876"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Oracle Linux 6",
                "product": {
                  "name": "Oracle Linux 6",
                  "product_id": "Oracle-Linux-6",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:oracle:linux:6:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Oracle Linux"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "busybox-petitboot-1:1.15.1-21.el6_6.x86_64",
                "product": {
                  "name": "busybox-petitboot-1:1.15.1-21.el6_6.x86_64",
                  "product_id": "busybox-petitboot-1:1.15.1-21.el6_6.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/oracle/busybox-petitboot@1.15.1-21.el6_6?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "busybox-1:1.15.1-21.el6_6.x86_64",
                "product": {
                  "name": "busybox-1:1.15.1-21.el6_6.x86_64",
                  "product_id": "busybox-1:1.15.1-21.el6_6.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/oracle/busybox@1.15.1-21.el6_6?arch=x86_64&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "Oracle Corporation"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "busybox-petitboot-1:1.15.1-21.el6_6.tuxcare.els2.x86_64",
                "product": {
                  "name": "busybox-petitboot-1:1.15.1-21.el6_6.tuxcare.els2.x86_64",
                  "product_id": "busybox-petitboot-1:1.15.1-21.el6_6.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/busybox-petitboot@1.15.1-21.el6_6.tuxcare.els2?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "busybox-petitboot-1:1.15.1-21.el6_6.tuxcare.els3.x86_64",
                "product": {
                  "name": "busybox-petitboot-1:1.15.1-21.el6_6.tuxcare.els3.x86_64",
                  "product_id": "busybox-petitboot-1:1.15.1-21.el6_6.tuxcare.els3.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/busybox-petitboot@1.15.1-21.el6_6.tuxcare.els3?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "busybox-petitboot-1:1.15.1-21.el6_6.tuxcare.els1.x86_64",
                "product": {
                  "name": "busybox-petitboot-1:1.15.1-21.el6_6.tuxcare.els1.x86_64",
                  "product_id": "busybox-petitboot-1:1.15.1-21.el6_6.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/busybox-petitboot@1.15.1-21.el6_6.tuxcare.els1?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "busybox-1:1.15.1-21.el6_6.tuxcare.els2.x86_64",
                "product": {
                  "name": "busybox-1:1.15.1-21.el6_6.tuxcare.els2.x86_64",
                  "product_id": "busybox-1:1.15.1-21.el6_6.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/busybox@1.15.1-21.el6_6.tuxcare.els2?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "busybox-1:1.15.1-21.el6_6.tuxcare.els3.x86_64",
                "product": {
                  "name": "busybox-1:1.15.1-21.el6_6.tuxcare.els3.x86_64",
                  "product_id": "busybox-1:1.15.1-21.el6_6.tuxcare.els3.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/busybox@1.15.1-21.el6_6.tuxcare.els3?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "busybox-1:1.15.1-21.el6_6.tuxcare.els1.x86_64",
                "product": {
                  "name": "busybox-1:1.15.1-21.el6_6.tuxcare.els1.x86_64",
                  "product_id": "busybox-1:1.15.1-21.el6_6.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/busybox@1.15.1-21.el6_6.tuxcare.els1?arch=x86_64&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "CloudLinux"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "busybox-petitboot-1:1.15.1-21.el6_6.tuxcare.els2.x86_64 as a component of Oracle Linux 6",
          "product_id": "Oracle-Linux-6:busybox-petitboot-1:1.15.1-21.el6_6.tuxcare.els2.x86_64"
        },
        "product_reference": "busybox-petitboot-1:1.15.1-21.el6_6.tuxcare.els2.x86_64",
        "relates_to_product_reference": "Oracle-Linux-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "busybox-petitboot-1:1.15.1-21.el6_6.tuxcare.els3.x86_64 as a component of Oracle Linux 6",
          "product_id": "Oracle-Linux-6:busybox-petitboot-1:1.15.1-21.el6_6.tuxcare.els3.x86_64"
        },
        "product_reference": "busybox-petitboot-1:1.15.1-21.el6_6.tuxcare.els3.x86_64",
        "relates_to_product_reference": "Oracle-Linux-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "busybox-petitboot-1:1.15.1-21.el6_6.tuxcare.els1.x86_64 as a component of Oracle Linux 6",
          "product_id": "Oracle-Linux-6:busybox-petitboot-1:1.15.1-21.el6_6.tuxcare.els1.x86_64"
        },
        "product_reference": "busybox-petitboot-1:1.15.1-21.el6_6.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Oracle-Linux-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "busybox-1:1.15.1-21.el6_6.tuxcare.els2.x86_64 as a component of Oracle Linux 6",
          "product_id": "Oracle-Linux-6:busybox-1:1.15.1-21.el6_6.tuxcare.els2.x86_64"
        },
        "product_reference": "busybox-1:1.15.1-21.el6_6.tuxcare.els2.x86_64",
        "relates_to_product_reference": "Oracle-Linux-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "busybox-1:1.15.1-21.el6_6.tuxcare.els3.x86_64 as a component of Oracle Linux 6",
          "product_id": "Oracle-Linux-6:busybox-1:1.15.1-21.el6_6.tuxcare.els3.x86_64"
        },
        "product_reference": "busybox-1:1.15.1-21.el6_6.tuxcare.els3.x86_64",
        "relates_to_product_reference": "Oracle-Linux-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "busybox-1:1.15.1-21.el6_6.tuxcare.els1.x86_64 as a component of Oracle Linux 6",
          "product_id": "Oracle-Linux-6:busybox-1:1.15.1-21.el6_6.tuxcare.els1.x86_64"
        },
        "product_reference": "busybox-1:1.15.1-21.el6_6.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Oracle-Linux-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "busybox-petitboot-1:1.15.1-21.el6_6.x86_64 as a component of Oracle Linux 6",
          "product_id": "Oracle-Linux-6:busybox-petitboot-1:1.15.1-21.el6_6.x86_64"
        },
        "product_reference": "busybox-petitboot-1:1.15.1-21.el6_6.x86_64",
        "relates_to_product_reference": "Oracle-Linux-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "busybox-1:1.15.1-21.el6_6.x86_64 as a component of Oracle Linux 6",
          "product_id": "Oracle-Linux-6:busybox-1:1.15.1-21.el6_6.x86_64"
        },
        "product_reference": "busybox-1:1.15.1-21.el6_6.x86_64",
        "relates_to_product_reference": "Oracle-Linux-6"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-60876",
      "cwe": {
        "id": "CWE-284",
        "name": "Improper Access Control"
      },
      "notes": [
        {
          "category": "description",
          "text": "BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20).",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Oracle-Linux-6:busybox-1:1.15.1-21.el6_6.tuxcare.els1.x86_64",
          "Oracle-Linux-6:busybox-1:1.15.1-21.el6_6.tuxcare.els2.x86_64",
          "Oracle-Linux-6:busybox-1:1.15.1-21.el6_6.tuxcare.els3.x86_64",
          "Oracle-Linux-6:busybox-1:1.15.1-21.el6_6.x86_64",
          "Oracle-Linux-6:busybox-petitboot-1:1.15.1-21.el6_6.tuxcare.els1.x86_64",
          "Oracle-Linux-6:busybox-petitboot-1:1.15.1-21.el6_6.tuxcare.els2.x86_64",
          "Oracle-Linux-6:busybox-petitboot-1:1.15.1-21.el6_6.tuxcare.els3.x86_64",
          "Oracle-Linux-6:busybox-petitboot-1:1.15.1-21.el6_6.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-60876"
        },
        {
          "category": "external",
          "summary": "https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092",
          "url": "https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092"
        },
        {
          "category": "external",
          "summary": "https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm",
          "url": "https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm"
        },
        {
          "category": "external",
          "summary": "https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm",
          "url": "https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm"
        },
        {
          "category": "external",
          "summary": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html",
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
        }
      ],
      "release_date": "2025-11-10T20:15:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-08-03T11:33:44.817929Z",
          "details": "This issue is a client-side input-sanitization flaw in BusyBox’s wget applet (not GNU Wget) that only manifests if wget is invoked with a specially crafted URL containing raw control characters to split the request line. Successful abuse also depends on the receiving HTTP server accepting such malformed request-lines, which standards-compliant servers typically reject, limiting any practical header injection. With no code execution or privilege escalation and impact confined to tampering with an outbound request from an administrative CLI tool rather than an exposed service, this is low priority for enterprise VM/server deployments.",
          "product_ids": [
            "Oracle-Linux-6:busybox-1:1.15.1-21.el6_6.tuxcare.els1.x86_64",
            "Oracle-Linux-6:busybox-1:1.15.1-21.el6_6.tuxcare.els2.x86_64",
            "Oracle-Linux-6:busybox-1:1.15.1-21.el6_6.tuxcare.els3.x86_64",
            "Oracle-Linux-6:busybox-1:1.15.1-21.el6_6.x86_64",
            "Oracle-Linux-6:busybox-petitboot-1:1.15.1-21.el6_6.tuxcare.els1.x86_64",
            "Oracle-Linux-6:busybox-petitboot-1:1.15.1-21.el6_6.tuxcare.els2.x86_64",
            "Oracle-Linux-6:busybox-petitboot-1:1.15.1-21.el6_6.tuxcare.els3.x86_64",
            "Oracle-Linux-6:busybox-petitboot-1:1.15.1-21.el6_6.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "Oracle-Linux-6:busybox-1:1.15.1-21.el6_6.tuxcare.els1.x86_64",
            "Oracle-Linux-6:busybox-1:1.15.1-21.el6_6.tuxcare.els2.x86_64",
            "Oracle-Linux-6:busybox-1:1.15.1-21.el6_6.tuxcare.els3.x86_64",
            "Oracle-Linux-6:busybox-1:1.15.1-21.el6_6.x86_64",
            "Oracle-Linux-6:busybox-petitboot-1:1.15.1-21.el6_6.tuxcare.els1.x86_64",
            "Oracle-Linux-6:busybox-petitboot-1:1.15.1-21.el6_6.tuxcare.els2.x86_64",
            "Oracle-Linux-6:busybox-petitboot-1:1.15.1-21.el6_6.tuxcare.els3.x86_64",
            "Oracle-Linux-6:busybox-petitboot-1:1.15.1-21.el6_6.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}