Bug#1142472: busybox: CVE-2026-38752 CVE-2026-38753 CVE-2026-38754 CVE-2026-38755
Salvatore Bonaccorso <[email protected]> Mon, 20 Jul 2026 14:17:57 +0200
| Newsgroups | gmane.linux.debian.devel.boot |
|---|---|
| Message-ID | <178454987745.709483.15254167854804112600.reportbug__45769.2147044995$1784549971$gmane$org@eldamar.lan> |
Source: busybox Version: 1:1.38.0-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]> Hi, The following vulnerabilities were published for busybox. CVE-2026-38752[0]: | A stack overflow in the evaluate() function (editors/awk.c) of | BusyBox commit 371fe9 allows attackers to cause a Denial of Service | (DoS) via supplying a crafted AWK script. CVE-2026-38753[1]: | A use-after-free in the awk_sub() function (editors/awk.c) of | Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) | via supplying a crafted AWK script. CVE-2026-38754[2]: | A heap overflow in the ifsbreakup() function (shell/ash.c) of | Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) | via supplying a crafted input. CVE-2026-38755[3]: | A heap overflow in the evalcommand() function (shell/ash.c) of | Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) | via supplying a crafted input. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-38752 https://www.cve.org/CVERecord?id=CVE-2026-38752 [1] https://security-tracker.debian.org/tracker/CVE-2026-38753 https://www.cve.org/CVERecord?id=CVE-2026-38753 [2] https://security-tracker.debian.org/tracker/CVE-2026-38754 https://www.cve.org/CVERecord?id=CVE-2026-38754 [3] https://security-tracker.debian.org/tracker/CVE-2026-38755 https://www.cve.org/CVERecord?id=CVE-2026-38755 Please adjust the affected versions in the BTS as needed. Regards, Salvatore