busybox: BusyBox: Denial of Service via crafted AWK script
Published Jul 15, 2026
7.5
HIGHCVSS 3.1
EPSS 0.34%
Description
A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
Affected products
-
- Version 1.00StatusaffectedConstraints<=1.38.0
- Version
No data.
Red Hat Hardened Images
busybox-main-1.37.0-8.2.hum1
Fixed · RHSA-2026:42074
Red Hat Enterprise Linux 6
busybox
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | busybox-main-1.37.0-8.2.hum1 | Fixed | RHSA-2026:42074 |
| Red Hat Enterprise Linux 6 | busybox | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This Moderate flaw in BusyBox's AWK interpreter allows a denial of service. An attacker could provide a specially crafted AWK script, leading to a stack overflow and making the BusyBox instance unresponsive. This vulnerability primarily affects systems where BusyBox is configured to execute untrusted AWK scripts, limiting its broader impact.
Red Hat mitigation
For systems utilizing BusyBox, limit exposure by avoiding the execution of untrusted AWK scripts. Ensure that BusyBox instances are not configured to process arbitrary or untrusted AWK script input, particularly in environments where BusyBox is used for critical system functions.
References (8)
- http://busybox.com
- https://access.redhat.com/security/cve/CVE-2026-38752 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2501204 Issue Tracking
- https://busybox.net/
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44848 Advisory
- https://lists.busybox.net/pipermail/busybox/2026-June/092351.html Mailing ListPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-38752
- https://www.cve.org/CVERecord?id=CVE-2026-38752
| Link | Providers | Tags |
|---|---|---|
| http://busybox.com | ||
| https://access.redhat.com/security/cve/CVE-2026-38752 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2501204 | Issue Tracking | |
| https://busybox.net/ | ||
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44848 | Advisory | |
| https://lists.busybox.net/pipermail/busybox/2026-June/092351.html | Mailing ListPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-38752 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-38752 |
Change history (0)
No recorded changes yet.