top of page
perceptive_background_267k.jpg

BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhc…

Published:

3 May 2026 at 22:00:00

Alert date:

4 May 2026 at 19:04:04

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Network Infrastructure

BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler. Network-adjacent attackers can exploit this vulnerability by sending crafted DHCPv6 responses with malformed D6_OPT_DNS_SERVERS options. The vulnerability exists in the option_to_env() function due to incorrect heap buffer allocation calculations. Successful exploitation can lead to memory corruption, denial of service, or arbitrary code execution. The vulnerability particularly affects embedded systems without heap hardening protections.

Technical details

Mitigation steps:

Affected products:

BusyBox

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page