CVE-2026-38753: Use After Free
A use-after-free in the awksub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.36.1-25 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.36.1-26
Event History
Frequently Asked Questions
What is the severity of CVE-2026-38753?
CVE-2026-38753 has a severity rating of 26.
How does CVE-2026-38753 affect Busybox?
CVE-2026-38753 allows attackers to execute a Denial of Service (DoS) attack by supplying a crafted AWK script.
What is a use-after-free vulnerability in the context of CVE-2026-38753?
In CVE-2026-38753, a use-after-free vulnerability occurs in the awk_sub() function, leading to potential crashes or unintended behavior.
How can I mitigate CVE-2026-38753 in my Busybox deployment?
To mitigate CVE-2026-38753, update Busybox to a version that has addressed this vulnerability.
When was CVE-2026-38753 published?
CVE-2026-38753 was published on July 15, 2026.