Heap Buffer Overflow in BusyBox TLS Due to Montgomery Reduction Allocation Issues
CVE-2026-88830
7.5HIGH
What is CVE-2026-88830?
A flaw in the allocation process during the Montgomery reduction in BusyBox TLS can lead to a pre-authentication heap buffer overflow. This vulnerability is triggered when processing a specially crafted ClientKeyExchange message. An attacker may exploit this weakness, potentially leading to disruptive consequences for affected systems.