CVE-2016-2148: Buffer Overflow
Published Feb 9, 2017
·Updated
Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION6RD parsing.
Affected Software
12 affected componentsFixes available
Busybox Busybox<=1.24.2
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
F5 BIG-IP>=17.5.0<=17.5.1, >=17.1.0<=17.1.3
F5 BIG-IP>=16.1.0<=16.1.6
F5 BIG-IP>=15.1.0<=15.1.10
F5 F5OS-A>=1.8.0<=1.8.3, >=1.5.1<=1.5.4
1.8.4
debian/busybox
1:1.30.1-61:1.30.1-6+deb11u11:1.35.0-4+deb12u11:1.37.0-61:1.37.0-10.1
Remediation
Patch Available
Event History
Feb 9, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:15 PM
Description
Oct 14, 2025
Advisory Published
via F5·02:46 AM
Data Sourced
via F5·02:46 AM
DescriptionSeverityWeaknessAffected Software
Feb 20, 2026
Data Sourced
via Ubuntu·12:42 AM
RemedyDescriptionSeverityAffected Software
May 18, 2026
Data Sourced
via Debian·03:28 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this heap-based buffer overflow vulnerability?
The vulnerability ID for this heap-based buffer overflow vulnerability is CVE-2016-2148.
2
What is the severity rating of CVE-2016-2148?
CVE-2016-2148 has a severity rating of 9.8 (critical).
3
Which software versions are affected by CVE-2016-2148?
BusyBox versions before 1.25.0 are affected by CVE-2016-2148.
4
How can remote attackers exploit this vulnerability?
Remote attackers can exploit this vulnerability through vectors involving OPTION_6RD parsing.
5
Are there any remediation steps available for this vulnerability?
Yes, the affected software versions can be remediated by updating to the specified fixed versions.