CVE Vulnerabilities

CVE-2026-38752

Uncontrolled Recursion

Published: Jul 15, 2026 | Modified: Jul 20, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.

Weakness

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Affected Software

NameVendorStart VersionEnd Version
BusyboxBusybox2024-07-13 (including)2024-07-13 (including)
Red Hat Hardened ImagesRedHatbusybox-main-1.37.0-8.2.hum1*

Potential Mitigations

References