Buffer Overflow in BusyBox TLS ClientHello Processing
CVE-2026-88840

5.3MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
23 September 2026

What is CVE-2026-88840?

A buffer overflow vulnerability exists in BusyBox TLS within the get_client_hello() function. This issue arises when parsing a truncated ClientHello message, leading the function to read beyond the allocated input buffer. Such behavior can potentially be exploited to affect application stability and may open avenues for unauthorized access or additional vulnerabilities, highlighting the importance of proper input validation mechanisms.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.