https://seclists.org/oss-sec/2026/q3/556: BusyBox dpkg applet: OS command injection
Published Aug 24, 2026
·Updated
Affected Software
1 affected component
Busybox Busybox>=1.36.1<=1.37.0
Frequently Asked Questions
1
Does this issue allow an unprivileged user to gain root privileges?
No privilege boundary is crossed. Commands run with the privileges of the user invoking the BusyBox dpkg applet; this is typically root when dpkg is run by an administrator.
2
Which BusyBox versions are known to be affected?
The issue was confirmed on BusyBox 1.36.1 and 1.37.0.git HEAD. The report states that it is present through current BusyBox.