REDHAT-BUG-2531344: Buffer Overflow

Published Sep 10, 2026
·
Updated

A vulnerability was found in the BusyBox TLS implementation (networking/tlspstmmontgomeryreduce.c). A unit confusion error exists in the buffer allocation for the Montgomery reduction operation. The code calls xzalloc(2pa+1) where pa is measured in pstmdigit units (4 or 8 bytes each), but the allocation treats this value as a byte count. This results in an allocation approximately 4x to 8x smaller than required.

When a TLS client sends a crafted ClientKeyExchange message with an all-zeros payload, the RSA decryption path triggers the Montgomery reduction, which writes digit-sized elements beyond the allocated buffer boundary. This constitutes a pre-authentication out-of-bounds heap write.

The confirmed impact is a pre-authentication denial of service (crash). While the heap buffer overflow is theoretically exploitable for remote code execution, this was not demonstrated. On Fedora, system-level mitigations including ASLR, PIE, full RELRO, and SELinux confinement make practical code execution extremely unlikely.

Affected Software

1 affected component
Busybox Busybox

Event History

Sep 10, 2026
Data Sourced
via Red Hat·09:45 AM
DescriptionSeverityAffected Software

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203