CVE-2026-38754

Published: July 18, 2026Last modified: August 11, 2026

Description

A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

Severity score breakdown

ParameterValue
Base score5.1
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactNONE
Availability impactLOW
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSbusyboxFixed (1.35.0-r41)
25 LTSbusyboxFixed (1.37.0-r28)
StreambusyboxFixed (1.38.0-r1)
Hardened Containers23 LTSbusyboxFixed (1.35.0-r41)
25 LTSbusyboxFixed (1.37.0-r28)
StreambusyboxFixed (1.38.0-r1)

References

ON THIS PAGE