


Perceptive Security
SOC/SIEM Consultancy

BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhc…
Published:
3 mei 2026 om 22:00:00
Alert date:
4 mei 2026 om 19:04:04
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure
BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler. Network-adjacent attackers can exploit this vulnerability by sending crafted DHCPv6 responses with malformed D6_OPT_DNS_SERVERS options. The vulnerability exists in the option_to_env() function due to incorrect heap buffer allocation calculations. Successful exploitation can lead to memory corruption, denial of service, or arbitrary code execution. The vulnerability particularly affects embedded systems without heap hardening protections.
Technical details
Mitigation steps:
Affected products:
BusyBox
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-29004
https://busybox.net/
https://github.com/vda-linux/busybox_mirror/commit/42202bfb1e6ac51fa995beda8be4d7b654aeee2a
https://github.com/vda-linux/busybox_mirror/commit/d368f3f7836d1c2484c8f839316e5c93e76d4409
https://www.vulncheck.com/advisories/busybox-dhcpv6-client-heap-buffer-overflow-via-dns-servers
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
