BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
Avoid processing untrusted filesystem images with BusyBox blkid or findfs. Use the util-linux versions of these utilities instead (default on Fedora).
References
History
Wed, 23 Sep 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images. | |
| Title | Busybox: busybox: romfs volume id parsing performs unbounded memcpy into fixed-size label buffer, causing heap overflow | |
| First Time appeared |
Redhat
Redhat hummingbird |
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:/a:redhat:hummingbird:1 | |
| Vendors & Products |
Redhat
Redhat hummingbird |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-23T17:41:09.077Z
Reserved: 2026-09-10T09:42:04.559Z
Link: CVE-2026-88832
No data.
Status : Received
Published: 2026-09-23T17:17:18.573
Modified: 2026-09-23T17:17:18.573
Link: CVE-2026-88832
No data.
OpenCVE Enrichment
No data.
Weaknesses