CVE-2026-38752: High severity busybox vulnerability
A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.36.1-25 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.36.1-26
Event History
Frequently Asked Questions
What is the severity of CVE-2026-38752?
CVE-2026-38752 has a risk rating of 26, indicating a significant vulnerability.
How do I fix CVE-2026-38752?
To fix CVE-2026-38752, update BusyBox to the latest version that addresses this stack overflow issue.
What type of vulnerability is CVE-2026-38752?
CVE-2026-38752 is a stack overflow vulnerability that can lead to Denial of Service (DoS).
What component of BusyBox is affected by CVE-2026-38752?
CVE-2026-38752 affects the evaluate() function in the editors/awk.c component of BusyBox.
How can an attacker exploit CVE-2026-38752?
An attacker can exploit CVE-2026-38752 by supplying a crafted AWK script that triggers the stack overflow.