CVE-2026-88832: Busybox: busybox: romfs volume id parsing performs unbounded memcpy into fixed-size label buffer, causing heap overflow

Published Sep 10, 2026
·
Updated

A vulnerability was found in the BusyBox romfs filesystem volume identification module (util-linux/volumeid/romfs.c). When parsing a romfs superblock, the code calls strlen() on attacker-controlled volume name metadata without any bounds checking. The resulting length is passed to memcpy() via volumeidsetlabelstring(), which copies the data into a fixed-size label field of approximately 65 bytes.

A crafted romfs filesystem image can contain a volume name of up to approximately 4080 bytes. When such an image is processed by blkid or findfs, the unbounded memcpy() writes far beyond the label buffer boundary, corrupting adjacent heap memory.

Other sources

BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images.

— MITRE

Busybox: busybox: romfs volume id parsing performs unbounded memcpy into fixed-size label buffer, causing heap overflow

— Microsoft

Affected Software

1 affected component
Busybox Busybox

Event History

Sep 10, 2026
Data Sourced
via Red Hat·09:46 AM
DescriptionSeverityAffected Software
Sep 23, 2026
CVE Published
via MITRE·05:05 PM
Data Sourced
via MITRE·05:05 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Oct 1, 2026
Data Sourced
via Microsoft·08:06 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is realistically exposed to this issue?

Systems using BusyBox components that identify ROMFS filesystems are exposed when they process untrusted or attacker-supplied ROMFS images. The described affected paths include processing an image with blkid or findfs.

2

What must an attacker do to trigger the overflow?

The attacker needs to provide a crafted ROMFS filesystem image with an oversized volume-name field and have it processed by the vulnerable ROMFS volume-identification code. The supplied severity vector indicates local access, low privileges, and user interaction are required.

3

What is the impact if a crafted image is processed?

The oversized volume name can cause an unbounded memcpy to overwrite heap memory beyond the fixed-size label buffer. This can corrupt adjacent heap memory and is rated as having high confidentiality, integrity, and availability impact.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203