Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-38752

Опубликовано: 15 июл. 2026
Источник: redhat
CVSS3: 6.5

Описание

A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.

A flaw was found in BusyBox. This vulnerability, a stack overflow in the evaluate() function, allows a remote attacker to cause a Denial of Service (DoS) by providing a specially crafted AWK script. A Denial of Service attack can make the affected system or application unavailable to legitimate users.

Отчет

This Moderate flaw in BusyBox's AWK interpreter allows a denial of service. An attacker could provide a specially crafted AWK script, leading to a stack overflow and making the BusyBox instance unresponsive. This vulnerability primarily affects systems where BusyBox is configured to execute untrusted AWK scripts, limiting its broader impact.

Меры по смягчению последствий

For systems utilizing BusyBox, limit exposure by avoiding the execution of untrusted AWK scripts. Ensure that BusyBox instances are not configured to process arbitrary or untrusted AWK script input, particularly in environments where BusyBox is used for critical system functions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6busyboxOut of support scope
Red Hat Hardened Imagesbusybox-main-1.37.0-8.2.hum1FixedRHSA-2026:4207420.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2501204busybox: BusyBox: Denial of Service via crafted AWK script

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 2.9
ubuntu
22 дня назад

A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.

CVSS3: 2.9
nvd
22 дня назад

A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.

CVSS3: 2.9
msrc
17 дней назад

A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.

CVSS3: 2.9
debian
22 дня назад

A stack overflow in the evaluate() function (editors/awk.c) of BusyBox ...

CVSS3: 7.5
github
22 дня назад

A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.

6.5 Medium

CVSS3