REDHAT-BUG-2531345: High severity Busybox Busybox vulnerability

Published Sep 10, 2026
·
Updated

A vulnerability was found in the BusyBox romfs filesystem volume identification module (util-linux/volumeid/romfs.c). When parsing a romfs superblock, the code calls strlen() on attacker-controlled volume name metadata without any bounds checking. The resulting length is passed to memcpy() via volumeidsetlabelstring(), which copies the data into a fixed-size label field of approximately 65 bytes.

A crafted romfs filesystem image can contain a volume name of up to approximately 4080 bytes. When such an image is processed by blkid or findfs, the unbounded memcpy() writes far beyond the label buffer boundary, corrupting adjacent heap memory.

Affected Software

1 affected component
Busybox Busybox

Event History

Sep 10, 2026
Data Sourced
via Red Hat·09:46 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Which systems and workflows are exposed?

Systems that use the BusyBox romfs volume identification module and process romfs filesystem images with blkid or findfs are exposed to the vulnerable parsing path.

2

What does an attacker need to exploit this issue?

An attacker needs to provide a crafted romfs filesystem image containing an oversized volume name and cause it to be processed by blkid or findfs. The crafted name can be approximately 4080 bytes, while the destination label field is approximately 65 bytes.

3

What is the immediate effect of successful exploitation?

Processing the malicious image causes an unbounded copy beyond the fixed-size label buffer, corrupting adjacent heap memory.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203