216.73.216.197

CVE-2026-29004

· Published 04/05/2026 18:16 · Modified 04/05/2026 18:16

Labels: CVE-2026-29004 2026-05-04CVE-2026-29004CWE-122[email protected]

Essential information

Published
04/05/2026 18:16
Modified
04/05/2026 18:16
Author
Creator
CVSS
7.2 HIGH (v3) 7.2 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhcpc.c that allows network-adjacent attackers to trigger memory corruption by sending a crafted DHCPv6 response with a malformed D6_OPT_DNS_SERVERS option. Attackers can exploit incorrect heap buffer allocation calculations in the option_to_env() function to cause denial of service or achieve arbitrary code execution on embedded systems without heap hardening.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
busybox / busybox cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*

References