CVE-2026-38754: High severity Busybox Busybox vulnerability
A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.36.1-25
Event History
Frequently Asked Questions
What is the severity of CVE-2026-38754?
CVE-2026-38754 has a risk rating of 26, indicating a significant potential impact.
How does CVE-2026-38754 allow attackers to exploit the system?
CVE-2026-38754 allows attackers to exploit the system by causing a Denial of Service through a crafted input to the ifsbreakup() function.
What software versions are affected by CVE-2026-38754?
CVE-2026-38754 affects Busybox version 1.38.0.
How do I fix CVE-2026-38754?
To fix CVE-2026-38754, users should update to a patched version of Busybox that addresses this heap overflow vulnerability.
What kind of vulnerability is CVE-2026-38754 classified as?
CVE-2026-38754 is classified as a heap overflow vulnerability that can lead to Denial of Service.