Bug#1142472: marked as done (busybox: CVE-2026-38752 CVE-2026-38753 CVE-2026-38754 CVE-2026-38755)
"Debian Bug Tracking System" <[email protected]> Sun, 26 Jul 2026 06:21:02 +0000
| Newsgroups | gmane.linux.debian.devel.boot |
|---|---|
| Message-ID | <handler.1142472.D1142472.1785046729722832.ackdone@bugs.debian.org> |
This is a multi-part message in MIME format... ------------=_1785046862-723993-0 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Your message dated Sun, 26 Jul 2026 06:18:45 +0000 with message-id <[email protected]> and subject line Bug#1142472: fixed in busybox 1:1.38.0-3 has caused the Debian Bug report #1142472, regarding busybox: CVE-2026-38752 CVE-2026-38753 CVE-2026-38754 CVE-2026-38= 755 to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact [email protected] immediately.) --=20 1142472: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D1142472 Debian Bug Tracking System Contact [email protected] with problems ------------=_1785046862-723993-0 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at submit) by bugs.debian.org; 20 Jul 2026 12:18:01 +0000 X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02 (2024-03-25) on buxtehude.debian.org X-Spam-Level: X-Spam-Status: No, score=-10.0 required=4.0 tests=BAYES_00,FROMDEVELOPER, NO_RELAYS,XMAILER_REPORTBUG autolearn=ham autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02 X-Spam-Bayes: score:0.0000 Tokens: new, 30; hammy, 135; neutral, 31; spammy, 1. spammytokens:0.941-+--H*r:bugs.debian.org hammytokens:0.000-+--XDebbugsCc, 0.000-+--X-Debbugs-Cc, 0.000-+--H*F:U*carnil, 0.000-+--H*Ad:N*Bug, 0.000-+--H*Ad:N*Tracking Return-path: <[email protected]> Received: via submission by buxtehude.debian.org with esmtp (Exim 4.96) (envelope-from <[email protected]>) id 1wlmwZ-004kJe-29 for [email protected]; Mon, 20 Jul 2026 12:18:01 +0000 Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit From: Salvatore Bonaccorso <[email protected]> To: Debian Bug Tracking System <[email protected]> Subject: busybox: CVE-2026-38752 CVE-2026-38753 CVE-2026-38754 CVE-2026-38755 Message-ID: <[email protected]> X-Mailer: reportbug 13.2.0+nmu1 Date: Mon, 20 Jul 2026 14:17:57 +0200 Delivered-To: [email protected] Source: busybox Version: 1:1.38.0-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]> Hi, The following vulnerabilities were published for busybox. CVE-2026-38752[0]: | A stack overflow in the evaluate() function (editors/awk.c) of | BusyBox commit 371fe9 allows attackers to cause a Denial of Service | (DoS) via supplying a crafted AWK script. CVE-2026-38753[1]: | A use-after-free in the awk_sub() function (editors/awk.c) of | Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) | via supplying a crafted AWK script. CVE-2026-38754[2]: | A heap overflow in the ifsbreakup() function (shell/ash.c) of | Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) | via supplying a crafted input. CVE-2026-38755[3]: | A heap overflow in the evalcommand() function (shell/ash.c) of | Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) | via supplying a crafted input. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-38752 https://www.cve.org/CVERecord?id=CVE-2026-38752 [1] https://security-tracker.debian.org/tracker/CVE-2026-38753 https://www.cve.org/CVERecord?id=CVE-2026-38753 [2] https://security-tracker.debian.org/tracker/CVE-2026-38754 https://www.cve.org/CVERecord?id=CVE-2026-38754 [3] https://security-tracker.debian.org/tracker/CVE-2026-38755 https://www.cve.org/CVERecord?id=CVE-2026-38755 Please adjust the affected versions in the BTS as needed. Regards, Salvatore ------------=_1785046862-723993-0 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at 1142472-close) by bugs.debian.org; 26 Jul 2026 06:18:49 +0000 X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02 (2024-03-25) on buxtehude.debian.org X-Spam-Level: X-Spam-Status: No, score=-114.2 required=4.0 tests=ALL_TRUSTED,BAYES_00, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FVGT_m_MULTI_ODD, HAS_BUG_NUMBER,MD5_SHA1_SUM,PGPSIGNATURE,SPF_HELO_PASS,SPF_PASS, USER_IN_DKIM_WELCOMELIST autolearn=ham autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02 X-Spam-Bayes: score:0.0000 Tokens: new, 119; hammy, 150; neutral, 120; spammy, 0. spammytokens: hammytokens:0.000-+--HX-Debian:DAK, 0.000-+--H*rp:D*ftp-master.debian.org, 0.000-+--HX-DAK:process-upload, 0.000-+--UD:debian.tar.xz, 0.000-+--H*r:sk:fasolo. Return-path: <[email protected]> Received: from mailly.debian.org ([2001:41b8:202:deb:6564:a62:52c3:4b72]:41854) by buxtehude.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim 4.96) (envelope-from <[email protected]>) id 1wnsCG-0031yD-2Y for [email protected]; Sun, 26 Jul 2026 06:18:49 +0000 Received: via submission from C=NA,ST=NA,L=Ankh Morpork,O=Debian SMTP,OU=Debian SMTP CA,CN=fasolo.debian.org,[email protected] (verified) by mailly.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim 4.96) (envelope-from <[email protected]>) id 1wnsCE-008P5B-2E for [email protected]; Sun, 26 Jul 2026 06:18:46 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=ftp-master.debian.org; s=smtpauto.fasolo; h=Date:Message-Id:Content-Type: Subject:MIME-Version:To:Reply-To:From:Cc:Content-Transfer-Encoding:Content-ID :Content-Description:In-Reply-To:References; bh=AOJNyXXf+nCaquhkQ8KTYGAAcjSJoROwGwcWyulq0Pw=; b=hCVvzOJvK5yc4OQpco83hc2V7Z 90BZqNJ1L7EHIg8FhkMG+YjZMv5iq+7zniEoqWbym2WYkN/wvPKQvLNdfIMaufnhVfCZPd/ALNfuT B9tpZeamCjovirYeVvBK5uXPBbhvY6vPmhnr4+G6FCsICm1g1wmEXaQ3LHZrA0YSeeNER43H3+l0M DUD5rg65R/K4+l1bXu/pw4wvny2F+zfWzIQEis0qQhaptY0XN1sOFBD5Z5mwBy3gufbh4qETG6v5t nbIMDO8TVOEbO0mqm3heKj8xQiY1MNfrPIZ7qepDnSqAFivh4INoFTAn1P2q0kX/0SAJluGIoW028 bAWsEySQ==; Received: from dak by fasolo.debian.org with local (Exim 4.98.2) (envelope-from <[email protected]>) id 1wnsCD-00000005GxU-1M8T; Sun, 26 Jul 2026 06:18:45 +0000 From: Debian FTP Masters <[email protected]> Reply-To: Michael Tokarev <[email protected]> To: [email protected] X-DAK: dak process-upload X-Debian: DAK X-Debian-Package: busybox Debian: DAK Debian-Changes: busybox_1.38.0-3_source.changes Debian-Source: busybox Debian-Version: 1:1.38.0-3 Debian-Architecture: source Debian-Suite: unstable Debian-Archive-Action: accept MIME-Version: 1.0 Subject: Bug#1142472: fixed in busybox 1:1.38.0-3 Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="===============1780600231318710141==" Message-Id: <[email protected]> Date: Sun, 26 Jul 2026 06:18:45 +0000 --===============1780600231318710141== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Source: busybox Source-Version: 1:1.38.0-3 Done: Michael Tokarev <[email protected]> We believe that the bug you reported is fixed in the latest version of busybox, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to [email protected], and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Michael Tokarev <[email protected]> (supplier of updated busybox package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing [email protected]) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 26 Jul 2026 08:53:18 +0300 Source: busybox Architecture: source Version: 1:1.38.0-3 Distribution: unstable Urgency: medium Maintainer: Debian Install System Team <[email protected]> Changed-By: Michael Tokarev <[email protected]> Closes: 1142472 Changes: busybox (1:1.38.0-3) unstable; urgency=3Dmedium . * fix 4 (minor) security issues (Closes: #1142472): - ash-fix-out-of-bounds-read-in-ifsbreakup-CVE-2026-38754.patch - ash-fix-stack-overflow-in-evalfun-CVE-2026-38755.patch - awk-fix-stack-overflow-in-evaluate-CVE-2026-38752.patch - awk-fix-use-after-free-in-awk_sub-CVE-2026-38753.patch Checksums-Sha1: f94c4b06a65a770d78de4691871f06eea9e9c861 2529 busybox_1.38.0-3.dsc 6ef8d237a825ed0a61fee4f68d42b19d4d3aca5d 2695723 busybox_1.38.0.orig.tar.bz2 101b46347e888a5603a7130d53534178aa04eeae 121 busybox_1.38.0.orig.tar.bz2.asc 8b89e7a76c911ba9176abccd48df758ed7d23f49 66644 busybox_1.38.0-3.debian.tar.xz d6266738a7d5c051da17abb8e4988e08d44b9b7d 5446 busybox_1.38.0-3_source.buildi= nfo Checksums-Sha256: 7c3b52b1dd3792b57681b26adfdaefab77de25f1d453e8ffb78187624a3bc57c 2529 busybo= x_1.38.0-3.dsc 34f9ea6ff8636f2c9241153b9114eefa9e65674a45318ae1ef95bb5f31c53bb2 2695723 bus= ybox_1.38.0.orig.tar.bz2 a496ee9653bc7faa0fd159f171b257bb6df612018fd8e50be83d956c16107a5b 121 busybox= _1.38.0.orig.tar.bz2.asc 9493090e7456abb7707a356ab71a810065b555fdeddc6f71d4dd1dc09ebc342f 66644 busyb= ox_1.38.0-3.debian.tar.xz c928cd517693833e572b3fa1a43d10da310f084139ad3f6447749976828a62a1 5446 busybo= x_1.38.0-3_source.buildinfo Files: 8daef02510b1aab0538bedbd2ac16818 2529 utils optional busybox_1.38.0-3.dsc 2a76df79da776a165bf85257403c97bc 2695723 utils optional busybox_1.38.0.orig.= tar.bz2 10550c8523d66769aa17f6a0e22d35a1 121 utils optional busybox_1.38.0.orig.tar.= bz2.asc 0cd800b73a8a0b09dfc59b9d1331383a 66644 utils optional busybox_1.38.0-3.debia= n.tar.xz c5c922f741cf252b95217336d90e91de 5446 utils optional busybox_1.38.0-3_source= .buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEZKoqtTHVaQM2a/75gqpKJDselHgFAmplpW8ACgkQgqpKJDse lHi7rQ//SVK7D3+DiboD30LtdtOvX+4uT7nHFRixrmvj5ZuSb5I4YLKAfBCvG1Kz o8rfpsZMroLZb4x7GYsMR+nPFjp5gz4Ug1yfg0eJzL/ds0C4TaRC/e2Y4YL5kC+8 jH/qaQNFmJ2EOWTbPejtDbFXrEY/TV+xy2MlKS/EDjLQTWQIEzkBzytDjYSm9tPg Z5A/6//ySQ0esfKUWBHfnOp1UcoWnO9Lnu+pQL4fVot55SZwyoVN9ynqAViVQ48V X3OUeQWobqksOaq9QsE/++GKmb/btds0RTtCK/+LOSfXO4slyHPjSLXo0LWkfAG2 HW2dJrzVHxode3tv3FNQ+g/p1/zQSDLB4V5WRXz6m/JUU1KDOMPx1LtuUhcxJY5i QcBganvTL62Mo3PS/dA5AwOczHiR5rmkpvJ6U36IwxlUsxEqWCdDX9WvYELsfM3J cVYxA9NBt4aCIrzJqnry9NzE4JQxOu7/k4EH+BsJ1sSTfECckWJI262TZqxwHLG8 +A12g7VvdaOysrQSZBwnDk3dNWoSWGVsglxEocaqqVM10ZIhZCORNMRPG/fSPCGr /ndfENwtW3cqvVevnAymZL0zOTZn7BB9BETaLxZJV0GwNFjfCpZLfD7gREeXGeLF zPGGATsmJkmDF7bwYS3EBJoIcg1IN63fZpA8h+ynqMKpNKMmsCg=3D =3DC587 -----END PGP SIGNATURE----- --===============1780600231318710141== Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCamWmxQAKCRCb9qggYcy5 Ia6MAP9DK1Wrz5s29IOI/yD1SB8d/sAGXIksmXaX6+MILnv/TwEAnS3hFCn5ii2p 7Z9dn/oVXmmB5kfQiw7DKbXTrSKJdQA= =vIga -----END PGP SIGNATURE----- --===============1780600231318710141==-- ------------=_1785046862-723993-0--