CVE-2026-88839: Busybox: busybox: passwd/group parser writes heap pointers out of bounds due to stale tokenize() endpoint
A vulnerability exists in the BusyBox passwd and group file parser in libpwdgrp/pwdgrp.c. The tokenize() function trims trailing whitespace via overlappingstrcpy() but continues to reference the stale end pointer, causing tokenizeend to be too large. This under-allocates in parsecommon(), and converttostruct() then writes grmem[] pointers past the end of the heap allocation.
Triggering the vulnerability requires injecting malformed entries with whitespace before commas into /etc/group, then invoking any applet that calls getgrnam().
Other sources
BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers.
— MITRE
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Systems using the BusyBox passwd/group parser are exposed when an attacker or untrusted process can inject malformed entries into /etc/group. The malformed entry must contain whitespace before commas, and a BusyBox applet must subsequently call getgrnam().
What access does an attacker need to trigger the out-of-bounds write?
The supplied vector requires local access and high privileges. Exploitation requires the ability to modify /etc/group with a specially malformed group entry; no user interaction is required.
How can I tell whether a system may have been exposed to exploitation?
Inspect /etc/group for malformed entries containing whitespace immediately before comma-separated fields. Also identify whether BusyBox applets that call getgrnam() were invoked after such entries were present.