CVE-2026-88830: Busybox: busybox: tls montgomery reduction allocates bytes instead of digits, causing a pre-auth heap buffer overflow

Published Sep 10, 2026
·
Updated

A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow when processing a crafted ClientKeyExchange message.

Other sources

A vulnerability was found in the BusyBox TLS implementation (networking/tlspstmmontgomeryreduce.c). A unit confusion error exists in the buffer allocation for the Montgomery reduction operation. The code calls xzalloc(2pa+1) where pa is measured in pstmdigit units (4 or 8 bytes each), but the allocation treats this value as a byte count. This results in an allocation approximately 4x to 8x smaller than required.

When a TLS client sends a crafted ClientKeyExchange message with an all-zeros payload, the RSA decryption path triggers the Montgomery reduction, which writes digit-sized elements beyond the allocated buffer boundary. This constitutes a pre-authentication out-of-bounds heap write.

The confirmed impact is a pre-authentication denial of service (crash). While the heap buffer overflow is theoretically exploitable for remote code execution, this was not demonstrated. On Fedora, system-level mitigations including ASLR, PIE, full RELRO, and SELinux confinement make practical code execution extremely unlikely.

— Red Hat

Affected Software

1 affected component
Busybox Busybox

Event History

Sep 10, 2026
Data Sourced
via Red Hat·09:45 AM
DescriptionSeverityAffected Software
Sep 23, 2026
CVE Published
via MITRE·05:04 PM
Data Sourced
via MITRE·05:04 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What does an attacker need to exploit this issue?

An attacker only needs network access to a vulnerable BusyBox TLS service and can trigger the flaw before authentication by sending a crafted ClientKeyExchange message with an all-zero payload. No credentials or user interaction are required.

2

What is the confirmed impact?

The confirmed impact is a pre-authentication denial of service through a crash caused by an out-of-bounds heap write. Remote code execution is theoretically possible because the issue is a heap buffer overflow, but it was not demonstrated.

3

If patching is not immediately possible, what mitigations are indicated by the available information?

Restrict network access to BusyBox TLS services to trusted clients where possible, since exploitation requires an incoming crafted TLS handshake. Fedora system mitigations including ASLR, PIE, full RELRO, and SELinux confinement make practical code execution substantially harder, although they do not prevent the confirmed denial-of-service condition.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203