util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows local users to have unknown impact and attack vectors.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "busybox", "binary_version": "1:1.21.0-1ubuntu1" }, { "binary_name": "busybox-initramfs", "binary_version": "1:1.21.0-1ubuntu1" }, { "binary_name": "busybox-static", "binary_version": "1:1.21.0-1ubuntu1" }, { "binary_name": "busybox-syslogd", "binary_version": "1:1.21.0-1ubuntu1" }, { "binary_name": "busybox-udeb", "binary_version": "1:1.21.0-1ubuntu1" }, { "binary_name": "udhcpc", "binary_version": "1:1.21.0-1ubuntu1" }, { "binary_name": "udhcpd", "binary_version": "1:1.21.0-1ubuntu1" } ] }