Heap Overflow Vulnerability in Busybox by the BusyBox Vendor
CVE-2026-38755

2.9LOW

Key Information:

Vendor

Busybox

Status
Vendor
CVE Published:
15 July 2026

What is CVE-2026-38755?

A heap overflow vulnerability has been identified in the evalcommand() function of Busybox v1.38.0. This flaw can be exploited by attackers through specially crafted input, potentially leading to a Denial of Service (DoS) condition. It is crucial for users to review their implementations and update to secure versions of Busybox to mitigate this risk. For more information and updates, refer to BusyBox's official site.

Affected Version(s)

BusyBox 0.52 <= 1.38.0

References

CVSS V3.1

Score:
2.9
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.