OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-88832

HIGH · CVSS 7.3 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The vulnerability in BusyBox's romfs volume ID parsing allows for a heap buffer overflow due to unbounded string length handling of attacker-controlled metadata in crafted filesystem images. This could lead to arbitrary code execution or crashes, making it critical for organizations using BusyBox in their embedded systems or container environments to prioritize patching. Security teams should assess their deployments to mitigate potential exploitation risks.

CVE
CVE-2026-88832
Severity
HIGH
CVSS
7.3
EPSS
0.13%

Original NVD Description

BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images.