PT-2026-36890 · Busybox · Busybox

·

CVE-2026-29004

·

Published

2026-03-12

·

Updated

2026-06-02

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BusyBox versions prior to commit 42202bf
Description A heap buffer overflow exists in the DHCPv6 client (udhcpc6) DNS SERVERS option handler within the networking/udhcp/d6 dhcpc.c file. Network-adjacent attackers can trigger memory corruption by sending a crafted DHCPv6 response containing a malformed D6 OPT DNS SERVERS option. This is possible due to incorrect heap buffer allocation calculations in the option to env() function, which may lead to denial of service or arbitrary code execution on embedded systems that lack heap hardening.
Recommendations Update to the version containing commit 42202bf.

Exploit

Fix

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12834
CVE-2026-29004
ECHO-4D14-5E51-2C9B
OESA-2026-2357
OPENSUSE-SU-2026:10740-1
OPENSUSE-SU-2026:20883-1
RHSA-2026:30652
SUSE-SU-2026:2053-1
SUSE-SU-2026:2054-1
SUSE-SU-2026:2069-1
SUSE-SU-2026:21943-1
SUSE-SU-2026:22020-1
SUSE-SU-2026:2204-1

Affected Products

Busybox