SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-38754

MEDIUM · CVSS 5.1 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

A heap overflow vulnerability in the ifsbreakup() function of Busybox v1.38.0 can be exploited by attackers to induce a Denial of Service (DoS) through specially crafted input. Organizations utilizing this version of Busybox should prioritize patching to mitigate potential service disruptions.

CVE
CVE-2026-38754
Severity
MEDIUM
CVSS
5.1
EPSS
0.24%

Original NVD Description

A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

Related CVEs

Other vulnerabilities affecting the same vendor(s)