CVE-2026-38752

A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:busybox:busybox:2024-07-13:*:*:*:*:*:*:*

History

20 Jul 2026, 16:16

Type Values Removed Values Added
References
  • {'url': 'http://busybox.com', 'tags': ['Product'], 'source': 'cve@mitre.org'}
  • () https://busybox.net/ -

20 Jul 2026, 15:16

Type Values Removed Values Added
References () https://lists.busybox.net/pipermail/busybox/2026-June/092351.html - Mailing List, Vendor Advisory, Patch () https://lists.busybox.net/pipermail/busybox/2026-June/092351.html - Mailing List, Patch, Vendor Advisory
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 2.9
CWE CWE-674

16 Jul 2026, 19:58

Type Values Removed Values Added
First Time Busybox
Busybox busybox
References () http://busybox.com - () http://busybox.com - Product
References () https://lists.busybox.net/pipermail/busybox/2026-June/092351.html - () https://lists.busybox.net/pipermail/busybox/2026-June/092351.html - Mailing List, Vendor Advisory, Patch
CPE cpe:2.3:a:busybox:busybox:2024-07-13:*:*:*:*:*:*:*

16 Jul 2026, 16:19

Type Values Removed Values Added
CWE CWE-121
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

15 Jul 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-15 22:16

Updated : 2026-07-20 16:16


NVD link : CVE-2026-38752

Mitre link : CVE-2026-38752

CVE.ORG link : CVE-2026-38752


JSON object : View

Products Affected

busybox

  • busybox
CWE
CWE-674

Uncontrolled Recursion

CWE-121

Stack-based Buffer Overflow