Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-26157

Опубликовано: 11 фев. 2026
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file overwrite, potentially enabling code execution through the modification of sensitive system files.

Меры по смягчению последствий

As a prevention measure, avoid extracting archives from untrusted sources using BusyBox utilities. If extraction of untrusted archives is necessary, perform it within a highly isolated and restricted environment, such as a container with a read-only root filesystem and minimal privileges, to limit the potential impact of arbitrary file overwrites.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6busyboxOut of support scope
Red Hat Hardened Imagesbusybox-main-1.37.0-7.2.hum1FixedRHSA-2026:1383105.05.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-73
https://bugzilla.redhat.com/show_bug.cgi?id=2439039busybox: BusyBox: Arbitrary file overwrite and potential code execution via incomplete path sanitization

EPSS

Процентиль: 49%
0.00682
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
6 месяцев назад

A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file overwrite, potentially enabling code execution through the modification of sensitive system files.

CVSS3: 7
nvd
6 месяцев назад

A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file overwrite, potentially enabling code execution through the modification of sensitive system files.

CVSS3: 7
debian
6 месяцев назад

A flaw was found in BusyBox. Incomplete path sanitization in its archi ...

CVSS3: 7
github
6 месяцев назад

A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file overwrite, potentially enabling code execution through the modification of sensitive system files.

suse-cvrf
5 месяцев назад

Security update for busybox

EPSS

Процентиль: 49%
0.00682
Низкий

7 High

CVSS3