Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-29004

Опубликовано: 04 мая 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhcpc.c that allows network-adjacent attackers to trigger memory corruption by sending a crafted DHCPv6 response with a malformed D6_OPT_DNS_SERVERS option. Attackers can exploit incorrect heap buffer allocation calculations in the option_to_env() function to cause denial of service or achieve arbitrary code execution on embedded systems without heap hardening.

A flaw was found in BusyBox. A heap buffer overflow vulnerability exists in the Dynamic Host Configuration Protocol version 6 (DHCPv6) client, specifically within the option_to_env() function. Network-adjacent attackers can exploit this by sending a crafted DHCPv6 response containing a malformed D6_OPT_DNS_SERVERS option. This can lead to memory corruption, potentially allowing for arbitrary code execution or denial of service on affected embedded systems lacking heap hardening.

Меры по смягчению последствий

To mitigate this vulnerability, restrict network access to systems running BusyBox as a DHCPv6 client, ensuring that only trusted DHCPv6 servers can communicate with it. If the DHCPv6 client functionality is not essential for the system's operation, consider disabling the udhcpc6 service or configuring it to only accept responses from known, trusted sources. Consult product-specific documentation for details on managing network services and configurations. Any changes to network service configurations may require a service restart to take effect, potentially impacting network connectivity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6busyboxNot affected
Red Hat Hardened Imagesbusybox-main-1.37.0-7.3.hum1FixedRHSA-2026:3065228.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-131
https://bugzilla.redhat.com/show_bug.cgi?id=2466526BusyBox: BusyBox: Arbitrary Code Execution via DHCPv6 Client Heap Buffer Overflow

EPSS

Процентиль: 31%
0.00375
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
3 месяца назад

BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhcpc.c that allows network-adjacent attackers to trigger memory corruption by sending a crafted DHCPv6 response with a malformed D6_OPT_DNS_SERVERS option. Attackers can exploit incorrect heap buffer allocation calculations in the option_to_env() function to cause denial of service or achieve arbitrary code execution on embedded systems without heap hardening.

CVSS3: 8.1
nvd
3 месяца назад

BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhcpc.c that allows network-adjacent attackers to trigger memory corruption by sending a crafted DHCPv6 response with a malformed D6_OPT_DNS_SERVERS option. Attackers can exploit incorrect heap buffer allocation calculations in the option_to_env() function to cause denial of service or achieve arbitrary code execution on embedded systems without heap hardening.

CVSS3: 8.1
debian
3 месяца назад

BusyBox before commit 42202bf contains a heap buffer overflow vulnerab ...

suse-cvrf
2 месяца назад

Security update for busybox

suse-cvrf
2 месяца назад

Security update for busybox

EPSS

Процентиль: 31%
0.00375
Низкий

8.8 High

CVSS3