A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
References
| Link | Resource |
|---|---|
| https://busybox.net/ | |
| https://lists.busybox.net/pipermail/busybox/2026-June/092351.html | Mailing List Patch Vendor Advisory |
Configurations
History
20 Jul 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
20 Jul 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://lists.busybox.net/pipermail/busybox/2026-June/092351.html - Mailing List, Patch, Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 2.9 |
| CWE | CWE-674 |
16 Jul 2026, 19:58
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Busybox
Busybox busybox |
|
| References | () http://busybox.com - Product | |
| References | () https://lists.busybox.net/pipermail/busybox/2026-June/092351.html - Mailing List, Vendor Advisory, Patch | |
| CPE | cpe:2.3:a:busybox:busybox:2024-07-13:*:*:*:*:*:*:* |
16 Jul 2026, 16:19
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-121 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
15 Jul 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-15 22:16
Updated : 2026-07-20 16:16
NVD link : CVE-2026-38752
Mitre link : CVE-2026-38752
CVE.ORG link : CVE-2026-38752
JSON object : View
Products Affected
busybox
- busybox
