Source: busybox Version: 1:1.38.0-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for busybox. CVE-2026-38752[0]: | A stack overflow in the evaluate() function (editors/awk.c) of | BusyBox commit 371fe9 allows attackers to cause a Denial of Service | (DoS) via supplying a crafted AWK script. CVE-2026-38753[1]: | A use-after-free in the awk_sub() function (editors/awk.c) of | Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) | via supplying a crafted AWK script. CVE-2026-38754[2]: | A heap overflow in the ifsbreakup() function (shell/ash.c) of | Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) | via supplying a crafted input. CVE-2026-38755[3]: | A heap overflow in the evalcommand() function (shell/ash.c) of | Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) | via supplying a crafted input. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-38752 https://www.cve.org/CVERecord?id=CVE-2026-38752 [1] https://security-tracker.debian.org/tracker/CVE-2026-38753 https://www.cve.org/CVERecord?id=CVE-2026-38753 [2] https://security-tracker.debian.org/tracker/CVE-2026-38754 https://www.cve.org/CVERecord?id=CVE-2026-38754 [3] https://security-tracker.debian.org/tracker/CVE-2026-38755 https://www.cve.org/CVERecord?id=CVE-2026-38755 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

