Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-26157

Опубликовано: 11 фев. 2026
Источник: redhat
CVSS3: 7

Описание

A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file overwrite, potentially enabling code execution through the modification of sensitive system files.

Меры по смягчению последствий

As a prevention measure, avoid extracting archives from untrusted sources using BusyBox utilities. If extraction of untrusted archives is necessary, perform it within a highly isolated and restricted environment, such as a container with a read-only root filesystem and minimal privileges, to limit the potential impact of arbitrary file overwrites.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6busyboxOut of support scope

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-73
https://bugzilla.redhat.com/show_bug.cgi?id=2439039busybox: BusyBox: Arbitrary file overwrite and potential code execution via incomplete path sanitization

7 High

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
около 1 месяца назад

A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file overwrite, potentially enabling code execution through the modification of sensitive system files.

CVSS3: 7
nvd
около 1 месяца назад

A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file overwrite, potentially enabling code execution through the modification of sensitive system files.

CVSS3: 7
debian
около 1 месяца назад

A flaw was found in BusyBox. Incomplete path sanitization in its archi ...

CVSS3: 7
github
около 1 месяца назад

A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file overwrite, potentially enabling code execution through the modification of sensitive system files.

suse-cvrf
25 дней назад

Security update for busybox

7 High

CVSS3