{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3abusyboxbusybox2024-07-13/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:busybox:busybox:2024-07-13:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":2.9,"id":"CVE-2026-38752"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["BusyBox (commit 371fe9)"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","vulnerability","linux","busybox"],"_cs_type":"advisory","_cs_vendors":["BusyBox"],"content_html":"\u003cp\u003eA significant stack overflow vulnerability, tracked as CVE-2026-38752, has been discovered in the \u003ccode\u003eevaluate()\u003c/code\u003e function of BusyBox's AWK utility. This flaw specifically affects BusyBox commit 371fe9 and resides within the \u003ccode\u003eeditors/awk.c\u003c/code\u003e source file. Attackers can exploit this vulnerability by supplying a carefully crafted AWK script to the BusyBox AWK interpreter. Successful exploitation leads to a Denial of Service (DoS) condition on the affected system, causing the BusyBox process, and potentially the entire system if critical services rely on it, to crash or become unresponsive. Given BusyBox's widespread use in embedded systems, IoT devices, and various Linux environments, this vulnerability could impact a broad range of devices and services. The vulnerability's impact stems from resource exhaustion caused by the stack overflow, making the targeted system unreliable or unavailable.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker gains the ability to execute an AWK script on a target system running an affected version of BusyBox. This could be through a web application accepting user-provided scripts, a compromised user account, or other means of remote execution.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious AWK script designed to trigger a stack overflow within the \u003ccode\u003eevaluate()\u003c/code\u003e function in \u003ccode\u003eeditors/awk.c\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe crafted AWK script is provided as input to the BusyBox AWK interpreter.\u003c/li\u003e\n\u003cli\u003eDuring the script's execution, the \u003ccode\u003eevaluate()\u003c/code\u003e function is called.\u003c/li\u003e\n\u003cli\u003eThe malicious script's input causes recursive or deeply nested operations within \u003ccode\u003eevaluate()\u003c/code\u003e, leading to excessive stack memory consumption.\u003c/li\u003e\n\u003cli\u003eThe stack overflow occurs, corrupting memory and causing the BusyBox AWK process to crash or become unresponsive.\u003c/li\u003e\n\u003cli\u003eThe system experiences a Denial of Service, affecting services or the entire device relying on the BusyBox utility.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-38752 results in a Denial of Service (DoS) condition on systems running affected BusyBox versions. This can manifest as the BusyBox process crashing or freezing, rendering services dependent on it inoperable. In embedded systems or IoT devices where BusyBox is a core component, this could lead to device unresponsiveness, requiring manual intervention such as a reboot. The primary impact is system instability and unavailability. While no specific victim counts or sectors are currently identified, the broad deployment of BusyBox in various critical infrastructure, industrial control systems, and consumer devices means the potential for widespread disruption exists.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-38752 by upgrading BusyBox to a version that includes the fix for the stack overflow vulnerability.\u003c/li\u003e\n\u003cli\u003eRestrict the execution of user-supplied or untrusted AWK scripts on systems using BusyBox to mitigate the attack vector for CVE-2026-38752.\u003c/li\u003e\n\u003cli\u003eMonitor system logs for unexpected BusyBox process crashes or restarts, which could indicate attempts to exploit CVE-2026-38752.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-21T07:29:56Z","date_published":"2026-07-21T07:29:56Z","id":"https://feed.craftedsignal.io/briefs/2026-07-busybox-awk-dos/","summary":"A stack overflow vulnerability, identified as CVE-2026-38752, exists in the evaluate() function within the AWK editor (editors/awk.c) of BusyBox commit 371fe9, which allows attackers to trigger a Denial of Service (DoS) condition by providing a specially crafted AWK script.","title":"BusyBox AWK Vulnerability Leads to Denial of Service","url":"https://feed.craftedsignal.io/briefs/2026-07-busybox-awk-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:busybox:busybox:2024-07-13:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}