A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
References
| Link | Resource |
|---|---|
| https://busybox.net | |
| https://lists.busybox.net/pipermail/busybox/2026-June/092354.html | Mailing List Patch Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-07-15 22:16
Updated : 2026-07-20 16:16
NVD link : CVE-2026-38755
Mitre link : CVE-2026-38755
CVE.ORG link : CVE-2026-38755
JSON object : View
Products Affected
busybox
- busybox
