Re: Information related to fix for CVE-2026-38753, CVE-2026-38754, CVE-2026-38755

Sanghyun Park via busybox <[email protected]> Fri, 24 Jul 2026 21:47:54 +0900
Newsgroups gmane.linux.busybox
Message-ID <[email protected]>
Hi,

Thanks for pointing to the patches, David.

Let me share the current upstream status:

- CVE-2026-38753: the patch was submitted but is not yet merged:
  https://lists.busybox.net/pipermail/busybox/2026-June/092352.html

- CVE-2026-38754: the final v3 patch was merged into upstream master
  as commit a448b6d5b21e5b21249391389b6f0551d9bea136:
  https://lists.busybox.net/pipermail/busybox/2026-June/092360.html

- CVE-2026-38755: the patch was submitted but is not yet merged:
  https://lists.busybox.net/pipermail/busybox/2026-June/092354.html

For severity clarification, the current MITRE CNA CVSS scores are:

- CVE-2026-38753: 4.9 Medium
- CVE-2026-38754: 5.1 Medium
- CVE-2026-38755: 2.9 Low

The CVE records currently also contain older CISA-ADP 7.5 High metrics.
This may explain why some scanners still report these vulnerabilities
as High.

Regards,
Sanghyun