CVE-2026-38754HighCVSS 7.5

A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

Published
July 23, 2026
Last Modified

🔗 CVE IDs covered (1)