Junglewise Threat Intelligence

CVE-2026-38753: BusyBox AWK use-after-free in awk_sub

CVE-2026-38753 · Severity: info · Published 2026-07-15

Technologies: Busybox. Vendors: Busybox.

Executive brief

BusyBox is a software suite that provides several Unix utilities in a single executable file, commonly used in embedded systems and Linux distributions. A flaw in its text-processing tool, AWK, could allow an attacker to crash the utility by providing a specially crafted script. This results in a denial-of-service, potentially disrupting automated system tasks or administrative operations that rely on AWK.

Technical details

A use-after-free (UAF) vulnerability exists in the awk_sub() function within editors/awk.c of BusyBox v1.38.0. The function receives a pointer to replacement text stored in AWK variable storage; however, evaluating the regular expression argument via as_regex() can trigger a reallocation or change in that storage, leaving the replacement pointer dangling. Subsequent calls to strlen() or the replacement loop then access this freed memory. An attacker who can provide a crafted AWK script to be executed by the vulnerable BusyBox binary can trigger a crash (Denial of Service). A patch has been proposed to copy the replacement string into stable storage before the regex evaluation occurs.

Affected products

  • BusyBox BusyBox 1.38.0

Timeline

  • 2026-06-16: patched: Patch submitted to BusyBox mailing list by Sanghyun Park
  • 2026-07-15: disclosed: CVE published to NVD

References

Related threats