Heap Buffer Overflow Vulnerability in BusyBox's DHCPv6 Client
CVE-2026-29004

7.2HIGH

Key Information:

Vendor

Vda-linux

Vendor
CVE Published:
4 May 2026

What is CVE-2026-29004?

A vulnerability in BusyBox's DHCPv6 client (udhcpc6) introduces a heap buffer overflow within the DNS_SERVERS option handler. This flaw permits network-adjacent attackers to craft malicious DHCPv6 responses containing malformed D6_OPT_DNS_SERVERS options. Exploiting this vulnerability could result in significant memory corruption, affecting the correct heap buffer allocation calculations in the option_to_env() function, potentially leading to denial of service or arbitrary code execution on embedded systems lacking robust heap protection mechanisms.

Affected Version(s)

busybox_mirror 0

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc.
VulnCheck
.