Re: Information related to fix for CVE-2026-38753, CVE-2026-38754, CVE-2026-38755
Sanghyun Park via busybox <[email protected]> Fri, 24 Jul 2026 21:47:54 +0900
| Newsgroups | gmane.linux.busybox |
|---|---|
| Message-ID | <[email protected]> |
Hi, Thanks for pointing to the patches, David. Let me share the current upstream status: - CVE-2026-38753: the patch was submitted but is not yet merged: https://lists.busybox.net/pipermail/busybox/2026-June/092352.html - CVE-2026-38754: the final v3 patch was merged into upstream master as commit a448b6d5b21e5b21249391389b6f0551d9bea136: https://lists.busybox.net/pipermail/busybox/2026-June/092360.html - CVE-2026-38755: the patch was submitted but is not yet merged: https://lists.busybox.net/pipermail/busybox/2026-June/092354.html For severity clarification, the current MITRE CNA CVSS scores are: - CVE-2026-38753: 4.9 Medium - CVE-2026-38754: 5.1 Medium - CVE-2026-38755: 2.9 Low The CVE records currently also contain older CISA-ADP 7.5 High metrics. This may explain why some scanners still report these vulnerabilities as High. Regards, Sanghyun