CVE-2026-88832: Busybox: busybox: romfs volume id parsing performs unbounded memcpy into fixed-size label buffer, causing heap overflow
A vulnerability was found in the BusyBox romfs filesystem volume identification module (util-linux/volumeid/romfs.c). When parsing a romfs superblock, the code calls strlen() on attacker-controlled volume name metadata without any bounds checking. The resulting length is passed to memcpy() via volumeidsetlabelstring(), which copies the data into a fixed-size label field of approximately 65 bytes.
A crafted romfs filesystem image can contain a volume name of up to approximately 4080 bytes. When such an image is processed by blkid or findfs, the unbounded memcpy() writes far beyond the label buffer boundary, corrupting adjacent heap memory.
Other sources
BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images.
— MITRE
Busybox: busybox: romfs volume id parsing performs unbounded memcpy into fixed-size label buffer, causing heap overflow
— Microsoft
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Systems using BusyBox components that identify ROMFS filesystems are exposed when they process untrusted or attacker-supplied ROMFS images. The described affected paths include processing an image with blkid or findfs.
What must an attacker do to trigger the overflow?
The attacker needs to provide a crafted ROMFS filesystem image with an oversized volume-name field and have it processed by the vulnerable ROMFS volume-identification code. The supplied severity vector indicates local access, low privileges, and user interaction are required.
What is the impact if a crafted image is processed?
The oversized volume name can cause an unbounded memcpy to overwrite heap memory beyond the fixed-size label buffer. This can corrupt adjacent heap memory and is rated as having high confidentiality, integrity, and availability impact.