Stack Overflow Vulnerability in BusyBox's AWK Script Processing
CVE-2026-38752

2.9LOW

Key Information:

Vendor

Busybox

Status
Vendor
CVE Published:
15 July 2026

What is CVE-2026-38752?

A security flaw in the BusyBox software allows for a stack overflow in the evaluate() function related to AWK script execution. By sending a specially crafted AWK script, attackers can trigger a Denial of Service (DoS) condition, potentially disrupting system functionality. Users of BusyBox should take immediate action to assess their installations and apply necessary updates to mitigate this vulnerability.

Affected Version(s)

BusyBox 1.00 <= 1.38.0

References

CVSS V3.1

Score:
2.9
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.