CVE-2026-88835: Busybox: busybox: dpkg read_package_field() steps past nul terminator, causing out-of-bounds read on malformed .deb packages
A vulnerability was found in the BusyBox dpkg implementation (archival/dpkg.c). The restart path in readpackagefield() incorrectly handles the case where a field has a name but an empty value followed by a NUL terminator, stepping one byte past the buffer and reading adjacent heap memory. This causes a bus error or segfault.
Other sources
BusyBox dpkg readpackagefield() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What must an attacker provide to trigger the issue?
The attacker must cause BusyBox dpkg to process a malformed .deb package containing a package field with a name, an empty value, and a following NUL terminator. Processing that package can make read_package_field() read one byte past the buffer.
What is the practical impact if the flaw is triggered?
The out-of-bounds heap read can cause BusyBox dpkg to terminate with a bus error or segmentation fault. The provided data describes a denial-of-service outcome and does not establish code execution or data modification.
Is remote access alone sufficient to exploit this vulnerability?
No. The supplied vector identifies local attack access and user interaction, and exploitation requires a malformed .deb package to be processed by the BusyBox dpkg implementation.