CVE-2026-88830: Busybox: busybox: tls montgomery reduction allocates bytes instead of digits, causing a pre-auth heap buffer overflow
A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow when processing a crafted ClientKeyExchange message.
Other sources
A vulnerability was found in the BusyBox TLS implementation (networking/tlspstmmontgomeryreduce.c). A unit confusion error exists in the buffer allocation for the Montgomery reduction operation. The code calls xzalloc(2pa+1) where pa is measured in pstmdigit units (4 or 8 bytes each), but the allocation treats this value as a byte count. This results in an allocation approximately 4x to 8x smaller than required.
When a TLS client sends a crafted ClientKeyExchange message with an all-zeros payload, the RSA decryption path triggers the Montgomery reduction, which writes digit-sized elements beyond the allocated buffer boundary. This constitutes a pre-authentication out-of-bounds heap write.
The confirmed impact is a pre-authentication denial of service (crash). While the heap buffer overflow is theoretically exploitable for remote code execution, this was not demonstrated. On Fedora, system-level mitigations including ASLR, PIE, full RELRO, and SELinux confinement make practical code execution extremely unlikely.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
An attacker only needs network access to a vulnerable BusyBox TLS service and can trigger the flaw before authentication by sending a crafted ClientKeyExchange message with an all-zero payload. No credentials or user interaction are required.
What is the confirmed impact?
The confirmed impact is a pre-authentication denial of service through a crash caused by an out-of-bounds heap write. Remote code execution is theoretically possible because the issue is a heap buffer overflow, but it was not demonstrated.
If patching is not immediately possible, what mitigations are indicated by the available information?
Restrict network access to BusyBox TLS services to trusted clients where possible, since exploitation requires an incoming crafted TLS handshake. Fedora system mitigations including ASLR, PIE, full RELRO, and SELinux confinement make practical code execution substantially harder, although they do not prevent the confirmed denial-of-service condition.