VYPR

rpm package

opensuse/busybox&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/busybox&distro=openSUSE%20Tumbleweed

Vulnerabilities (41)

  • CVE-2026-88839MedSep 23, 2026
    affected < 1.38.0-3.1fixed 1.38.0-3.1

    BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers.

  • CVE-2026-88837MedSep 23, 2026
    affected < 1.38.0-3.1fixed 1.38.0-3.1

    BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authentication check.

  • CVE-2026-88835MedSep 23, 2026
    affected < 1.38.0-3.1fixed 1.38.0-3.1

    BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read.

  • CVE-2026-88831MedSep 23, 2026
    affected < 1.38.0-3.1fixed 1.38.0-3.1

    BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no clients.

  • CVE-2026-88832HigSep 23, 2026
    affected < 1.38.0-3.1fixed 1.38.0-3.1

    BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images.

  • CVE-2026-88830HigSep 23, 2026
    affected < 1.38.0-3.1fixed 1.38.0-3.1

    A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow when processing a crafted ClientKeyExchange message.

  • CVE-2026-88841lowSep 23, 2026
    affected < 1.38.0-3.1fixed 1.38.0-3.1

    busybox: busybox: dpkg write_status_file() stale cursor causes out-of-bounds read and status file corruption

  • CVE-2026-38755LowJul 15, 2026
    affected < 1.38.0-2.1fixed 1.38.0-2.1

    A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

  • CVE-2026-38754MedJul 15, 2026
    affected < 1.38.0-2.1fixed 1.38.0-2.1

    A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

  • CVE-2026-38752LowJul 15, 2026
    affected < 1.38.0-2.1fixed 1.38.0-2.1

    A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.

  • CVE-2026-38753MedJul 15, 2026
    affected < 1.38.0-2.1fixed 1.38.0-2.1

    A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.

  • CVE-2026-29004HigMay 4, 2026
    affected < 1.37.0-11.1fixed 1.37.0-11.1

    BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhcpc.c that allows network-adjacent attackers to trigger memory corruption by sending a crafted DHCPv6 response with a mal

  • CVE-2026-26158HigFeb 11, 2026
    affected < 1.37.0-9.1fixed 1.37.0-9.1

    A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or symlink entries. If the tar archive is extracted with elevated privileges, this f

  • CVE-2026-26157HigFeb 11, 2026
    affected < 1.37.0-10.1fixed 1.37.0-10.1

    A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file over

  • CVE-2025-60876MedNov 10, 2025
    affected < 1.37.0-8.1fixed 1.37.0-8.1

    BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target

  • CVE-2025-46394LowApr 23, 2025
    affected < 1.37.0-8.1fixed 1.37.0-8.1

    In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.

  • CVE-2023-42366MedNov 27, 2023
    affected < 1.38.0-2.1fixed 1.38.0-2.1

    A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159.

  • CVE-2023-42365MedNov 27, 2023
    affected < 1.37.0-5.1fixed 1.37.0-5.1

    A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar function.

  • CVE-2023-42364MedNov 27, 2023
    affected < 1.37.0-5.1fixed 1.37.0-5.1

    A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function.

  • CVE-2023-42363MedNov 27, 2023
    affected < 1.37.0-5.1fixed 1.37.0-5.1

    A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1.

Page 1 of 3