Out-of-Bounds Write Vulnerability in BusyBox by Denial of Service
CVE-2026-88839
6.7MEDIUM
What is CVE-2026-88839?
The BusyBox utility experiences an out-of-bounds write vulnerability due to its passwd/group tokenize() function, which references a stale endpoint pointer. This flaw can lead to critical memory corruption and potentially trigger a denial of service, affecting the stability and integrity of systems running affected versions of BusyBox.