CVE-2026-38754

A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:busybox:busybox:1.38.0:*:*:*:*:*:*:*

History

20 Jul 2026, 16:16

Type Values Removed Values Added
References
  • {'url': 'https://busybox.com', 'tags': ['Product'], 'source': 'cve@mitre.org'}
  • () https://busybox.net -

20 Jul 2026, 15:16

Type Values Removed Values Added
CWE CWE-125
References () https://lists.busybox.net/pipermail/busybox/2026-June/092353.html - Mailing List, Vendor Advisory, Patch () https://lists.busybox.net/pipermail/busybox/2026-June/092353.html - Mailing List, Patch, Vendor Advisory
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 5.1

16 Jul 2026, 19:57

Type Values Removed Values Added
References () https://busybox.com - () https://busybox.com - Product
References () https://lists.busybox.net/pipermail/busybox/2026-June/092353.html - () https://lists.busybox.net/pipermail/busybox/2026-June/092353.html - Mailing List, Vendor Advisory, Patch
CPE cpe:2.3:a:busybox:busybox:1.38.0:*:*:*:*:*:*:*
First Time Busybox
Busybox busybox

16 Jul 2026, 16:19

Type Values Removed Values Added
CWE CWE-122
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

15 Jul 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-15 22:16

Updated : 2026-07-20 16:16


NVD link : CVE-2026-38754

Mitre link : CVE-2026-38754

CVE.ORG link : CVE-2026-38754


JSON object : View

Products Affected

busybox

  • busybox
CWE
CWE-125

Out-of-bounds Read

CWE-122

Heap-based Buffer Overflow