CVE-2026-88835: Busybox: busybox: dpkg read_package_field() steps past nul terminator, causing out-of-bounds read on malformed .deb packages

Published Sep 10, 2026
·
Updated

A vulnerability was found in the BusyBox dpkg implementation (archival/dpkg.c). The restart path in readpackagefield() incorrectly handles the case where a field has a name but an empty value followed by a NUL terminator, stepping one byte past the buffer and reading adjacent heap memory. This causes a bus error or segfault.

Other sources

BusyBox dpkg readpackagefield() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read.

— MITRE

Affected Software

1 affected component
Busybox Busybox

Event History

Sep 10, 2026
Data Sourced
via Red Hat·09:47 AM
DescriptionSeverityAffected Software
Sep 23, 2026
CVE Published
via MITRE·05:45 PM
Data Sourced
via MITRE·05:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What must an attacker provide to trigger the issue?

The attacker must cause BusyBox dpkg to process a malformed .deb package containing a package field with a name, an empty value, and a following NUL terminator. Processing that package can make read_package_field() read one byte past the buffer.

2

What is the practical impact if the flaw is triggered?

The out-of-bounds heap read can cause BusyBox dpkg to terminate with a bus error or segmentation fault. The provided data describes a denial-of-service outcome and does not establish code execution or data modification.

3

Is remote access alone sufficient to exploit this vulnerability?

No. The supplied vector identifies local attack access and user interaction, and exploitation requires a malformed .deb package to be processed by the BusyBox dpkg implementation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203