CVE-2026-38753

Name
CVE-2026-38753
Description
A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Product http://busybox.com
Mailing List https://lists.busybox.net/pipermail/busybox/2026-June/092352.html
cve@mitre.org https://busybox.net

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:busybox:busybox:1.38.0:*:*:*:*:*:*:* busybox == None == 1.38.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
busybox edge-main 1.38.0-r4 Sören Tempel <soeren+alpine@soeren-tempel.net> possibly vulnerable
busybox edge-main 1.38.0-r3 Sören Tempel <soeren+alpine@soeren-tempel.net> possibly vulnerable
busybox edge-main 1.38.0-r2 Sören Tempel <soeren+alpine@soeren-tempel.net> possibly vulnerable
busybox edge-main 1.38.0-r1 Sören Tempel <soeren+alpine@soeren-tempel.net> possibly vulnerable
busybox edge-main 1.38.0-r0 Sören Tempel <soeren+alpine@soeren-tempel.net> possibly vulnerable