VYPR

BusyBox

by Red Hat

CVEs (2)

  • CVE-2026-88832HigSep 23, 2026
    risk 0.47cvss 7.3epss 0.00

    BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images.

  • CVE-2026-88839MedSep 23, 2026
    risk 0.44cvss 6.7epss 0.00

    BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers.