CVE-2026-29004 Details
Description
BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhcpc.c that allows network-adjacent attackers to trigger memory corruption by sending a crafted DHCPv6 response with a malformed D6_OPT_DNS_SERVERS option. Attackers can exploit incorrect heap buffer allocation calculations in the option_to_env() function to cause denial of service or achieve arbitrary code execution on embedded systems without heap hardening.
A heap buffer overflow vulnerability has been identified in the BusyBox DHCPv6 client (udhcpc6) prior to commit 42202bf. The vulnerability resides in the DNS_SERVERS option handler within the file networking/udhcp/d6_dhcpc.c. This flaw allows network-adjacent attackers to cause memory corruption by sending a crafted DHCPv6 response with a malformed D6_OPT_DNS_SERVERS option. Exploitation takes advantage of incorrect heap buffer allocation calculations in the option_to_env() function, potentially leading to denial-of-service conditions or arbitrary code execution on embedded systems that lack heap hardening.
Users can update to BusyBox versions after the patch commit (42202bf) to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-122 | Heap-based Buffer Overflow | [email protected] |
| CWE-131 | Incorrect Calculation of Buffer Size | redhat-SADP |
Affected Products
No affected product data is available for this CVE.
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 6, 2026 | CVE Modified | [email protected] |
| May 4, 2026 | New CVE Received | [email protected] |