A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
References
| Link | Resource |
|---|---|
| https://busybox.net | |
| https://lists.busybox.net/pipermail/busybox/2026-June/092353.html | Mailing List Patch Vendor Advisory |
| https://lists.busybox.net/pipermail/busybox/2026-June/092360.html |
Configurations
History
No history.
Information
Published : 2026-07-15 22:16
Updated : 2026-07-22 15:16
NVD link : CVE-2026-38754
Mitre link : CVE-2026-38754
CVE.ORG link : CVE-2026-38754
JSON object : View
Products Affected
busybox
- busybox
