Heap Overflow Vulnerability in Busybox Affects Multiple Versions by Busybox
CVE-2026-38754
5.1MEDIUM
What is CVE-2026-38754?
A heap overflow vulnerability exists in the ifsbreakup() function within Busybox v1.38.0. This flaw can be exploited by attackers to induce a Denial of Service (DoS) condition by providing carefully crafted input. As a result, systems utilizing this version of Busybox may experience unexpected terminations or slowdowns, creating a potential disruption in service for users. It is crucial for users and administrators to review their systems for this vulnerability and consider appropriate mitigation strategies.
Affected Version(s)
BusyBox 1.00 <= 1.38.0
