In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim.
https://github.com/keyblxde/docker-cve-scanner
https://github.com/R16008882/CVE-checks-Yocto
https://www.busybox.net/downloads/