Back

HIGH

busybox: BusyBox: Denial of Service via crafted AWK script

Published Jul 15, 2026

Description

A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.

Affected products

Remediation

Red Hat statement

This Moderate flaw in BusyBox's AWK interpreter allows a denial of service. An attacker could provide a specially crafted AWK script, leading to a stack overflow and making the BusyBox instance unresponsive. This vulnerability primarily affects systems where BusyBox is configured to execute untrusted AWK scripts, limiting its broader impact.

Red Hat mitigation

For systems utilizing BusyBox, limit exposure by avoiding the execution of untrusted AWK scripts. Ensure that BusyBox instances are not configured to process arbitrary or untrusted AWK script input, particularly in environments where BusyBox is used for critical system functions.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 15, 2026
Updated Jul 20, 2026
Reserved Apr 6, 2026
CISA Vulnrichment
Updated Jul 16, 2026
NVD
Status Undergoing Analysis
Modified Jul 20, 2026
Red Hat
Severity Moderate
Public date Jul 15, 2026
ENISA EUVD
Assigner mitre
Published Jul 15, 2026
Updated Jul 20, 2026
Exploited since n/a
EUVD-2026-44848