CVE-2026-29004

Published: May 7, 2026Last modified: May 13, 2026

Description

BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhcpc.c that allows network-adjacent attackers to trigger memory corruption by sending a crafted DHCPv6 response with a malformed D6_OPT_DNS_SERVERS option. Attackers can exploit incorrect heap buffer allocation calculations in the option_to_env() function to cause denial of service or achieve arbitrary code execution on embedded systems without heap hardening.

Severity score breakdown

ParameterValue
Base score8.1
Attack VectorADJACENT_NETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSbusyboxFixed (1.35.0-r40)
25 LTSbusyboxFixed (1.37.0-r27)
StreambusyboxFixed (1.37.0-r37)
Hardened Containers23 LTSbusyboxFixed (1.35.0-r40)
25 LTSbusyboxFixed (1.37.0-r27)
StreambusyboxFixed (1.37.0-r37)

References

ON THIS PAGE