Описание
Security update for busybox
This update for busybox fixes the following issue
- CVE-2026-29004: Heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhcpc.c (bsc#1263989).
Список пакетов
Container bci/bci-busybox:latest
busybox-1.37.0-150700.18.18.1
busybox-adduser-1.37.0-150700.12.13.1
busybox-attr-1.37.0-150700.12.13.1
busybox-bc-1.37.0-150700.12.13.1
busybox-bind-utils-1.37.0-150700.12.13.1
busybox-bzip2-1.37.0-150700.12.13.1
busybox-coreutils-1.37.0-150700.12.13.1
busybox-cpio-1.37.0-150700.12.13.1
busybox-diffutils-1.37.0-150700.12.13.1
busybox-dos2unix-1.37.0-150700.12.13.1
busybox-ed-1.37.0-150700.12.13.1
busybox-findutils-1.37.0-150700.12.13.1
busybox-gawk-1.37.0-150700.12.13.1
busybox-grep-1.37.0-150700.12.13.1
busybox-gzip-1.37.0-150700.12.13.1
busybox-hexedit-1.37.0-150700.12.13.1
busybox-hostname-1.37.0-150700.12.13.1
busybox-iproute2-1.37.0-150700.12.13.1
busybox-iputils-1.37.0-150700.12.13.1
busybox-kbd-1.37.0-150700.12.13.1
busybox-less-1.37.0-150700.12.13.1
busybox-links-1.37.0-150700.12.13.1
busybox-man-1.37.0-150700.12.13.1
busybox-misc-1.37.0-150700.12.13.1
busybox-ncurses-utils-1.37.0-150700.12.13.1
busybox-net-tools-1.37.0-150700.12.13.1
busybox-netcat-1.37.0-150700.12.13.1
busybox-patch-1.37.0-150700.12.13.1
busybox-policycoreutils-1.37.0-150700.12.13.1
busybox-procps-1.37.0-150700.12.13.1
busybox-psmisc-1.37.0-150700.12.13.1
busybox-sed-1.37.0-150700.12.13.1
busybox-selinux-tools-1.37.0-150700.12.13.1
busybox-sendmail-1.37.0-150700.12.13.1
busybox-sh-1.37.0-150700.12.13.1
busybox-sha3sum-1.37.0-150700.12.13.1
busybox-sharutils-1.37.0-150700.12.13.1
busybox-syslogd-1.37.0-150700.12.13.1
busybox-sysvinit-tools-1.37.0-150700.12.13.1
busybox-tar-1.37.0-150700.12.13.1
busybox-telnet-1.37.0-150700.12.13.1
busybox-tftp-1.37.0-150700.12.13.1
busybox-time-1.37.0-150700.12.13.1
busybox-traceroute-1.37.0-150700.12.13.1
busybox-tunctl-1.37.0-150700.12.13.1
busybox-udhcpc-1.37.0-150700.12.13.1
busybox-unzip-1.37.0-150700.12.13.1
busybox-util-linux-1.37.0-150700.12.13.1
busybox-vi-1.37.0-150700.12.13.1
busybox-vlan-1.37.0-150700.12.13.1
busybox-wget-1.37.0-150700.12.13.1
busybox-which-1.37.0-150700.12.13.1
busybox-whois-1.37.0-150700.12.13.1
busybox-xz-1.37.0-150700.12.13.1
SUSE Linux Enterprise Module for Basesystem 15 SP7
busybox-1.37.0-150700.18.18.1
busybox-static-1.37.0-150700.18.18.1
Ссылки
- Link for SUSE-SU-2026:2054-1
- E-Mail link for SUSE-SU-2026:2054-1
- SUSE Security Ratings
- SUSE Bug 1263989
- SUSE CVE CVE-2026-29004 page
Описание
BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhcpc.c that allows network-adjacent attackers to trigger memory corruption by sending a crafted DHCPv6 response with a malformed D6_OPT_DNS_SERVERS option. Attackers can exploit incorrect heap buffer allocation calculations in the option_to_env() function to cause denial of service or achieve arbitrary code execution on embedded systems without heap hardening.
Затронутые продукты
Container bci/bci-busybox:latest:busybox-1.37.0-150700.18.18.1
Container bci/bci-busybox:latest:busybox-adduser-1.37.0-150700.12.13.1
Container bci/bci-busybox:latest:busybox-attr-1.37.0-150700.12.13.1
Container bci/bci-busybox:latest:busybox-bc-1.37.0-150700.12.13.1
Ссылки
- CVE-2026-29004
- SUSE Bug 1263989