Executive brief
BusyBox is a widely used software suite that provides essential command-line tools for embedded systems and Linux distributions. A vulnerability in its DHCPv6 client allows a nearby attacker on the same network to crash the system or potentially take full control of the device. This could lead to service outages or unauthorized access to sensitive data on IoT devices and industrial equipment.
Technical details
A heap-based buffer overflow (CWE-122) exists in the udhcpc6 DHCPv6 client within networking/udhcp/d6_dhcpc.c. The vulnerability is rooted in the option_to_env() function, where incorrect heap buffer allocation calculations occur when processing the D6_OPT_DNS_SERVERS option. Specifically, the code fails to allocate sufficient space for the formatted environment variable string. A network-adjacent attacker can exploit this by sending a crafted DHCPv6 response containing a malformed DNS_SERVERS option. On systems lacking modern heap hardening, this can lead to arbitrary code execution or a denial of service. The issue was addressed in commit 42202bf.
Affected products
- BusyBox BusyBox before commit 42202bf
- Red Hat Red Hat Hardened Images 1
Timeline
- 2026-05-04: disclosed
- 2026-05-04: advisory
- 2026-03-01: patched: Approximate date based on advisory text mentioning March 2026 patch.
References
- https://busybox.net/
- https://github.com/vda-linux/busybox_mirror/commit/42202bfb1e6ac51fa995beda8be4d7b654aeee2a
- https://github.com/vda-linux/busybox_mirror/commit/d368f3f7836d1c2484c8f839316e5c93e76d4409
- https://www.vulncheck.com/advisories/busybox-dhcpv6-client-heap-buffer-overflow-via-dns-servers
- https://y637f9qq2x.com/posts/busybox-dhcpv6-heap-overflow/
- https://access.redhat.com/errata/RHSA-2026:30652
- https://access.redhat.com/security/cve/CVE-2026-29004