REDHAT-BUG-2531349: Medium severity Busybox Busybox vulnerability
Published Sep 10, 2026
·Updated
A vulnerability was found in the BusyBox dpkg implementation (archival/dpkg.c). The restart path in readpackagefield() incorrectly handles the case where a field has a name but an empty value followed by a NUL terminator, stepping one byte past the buffer and reading adjacent heap memory. This causes a bus error or segfault.
Affected Software
1 affected component
Busybox Busybox
Event History
Sep 10, 2026
Data Sourced
via Red Hat·09:47 AM
DescriptionSeverityAffected Software