CVE-2026-38753

A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:busybox:busybox:1.38.0:*:*:*:*:*:*:*

History

20 Jul 2026, 16:16

Type Values Removed Values Added
References
  • {'url': 'http://busybox.com', 'tags': ['Product'], 'source': 'cve@mitre.org'}
  • () https://busybox.net -

20 Jul 2026, 15:16

Type Values Removed Values Added
References () https://lists.busybox.net/pipermail/busybox/2026-June/092352.html - Mailing List, Vendor Advisory, Patch () https://lists.busybox.net/pipermail/busybox/2026-June/092352.html - Mailing List, Patch, Vendor Advisory
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 4.9

16 Jul 2026, 19:58

Type Values Removed Values Added
First Time Busybox
Busybox busybox
CPE cpe:2.3:a:busybox:busybox:1.38.0:*:*:*:*:*:*:*
References () http://busybox.com - () http://busybox.com - Product
References () https://lists.busybox.net/pipermail/busybox/2026-June/092352.html - () https://lists.busybox.net/pipermail/busybox/2026-June/092352.html - Mailing List, Vendor Advisory, Patch

16 Jul 2026, 16:19

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-416

15 Jul 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-15 21:16

Updated : 2026-07-20 16:16


NVD link : CVE-2026-38753

Mitre link : CVE-2026-38753

CVE.ORG link : CVE-2026-38753


JSON object : View

Products Affected

busybox

  • busybox
CWE
CWE-416

Use After Free