LiveActive security incident?Get immediate response
CVE Record

CVE-2026-29004: BusyBox DHCPv6 Client Heap Buffer Overflow via DNS_SERVERS

BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhcpc.c that allows network-adjacent attackers to trigger memory corruption by sending a crafted DHCPv6 response with a malformed D6_OPT_DNS_SERVERS option. Attackers can exploit incorrect heap buffer allocation calculations in the option_to_env() function to cause denial of service or achieve arbitrary code execution on embedded systems without heap hardening.

HighCVSS 8.8Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

This vulnerability affects BusyBox’s DHCPv6 client, common in embedded Linux systems. A nearby attacker on the same network could send a malformed DHCPv6 response that corrupts memory. Reported impact includes denial of service and potential code execution, especially on systems without heap hardening.

Executive priority

Treat this as a high-priority infrastructure and embedded-device issue. It is not described as internet-routable, but local network compromise paths can matter in branch, IoT, OT, and appliance environments. Patch or validate vendor status promptly.

Technical view

BusyBox before commit 42202bf has a heap buffer overflow in udhcpc6 handling of D6_OPT_DNS_SERVERS in networking/udhcp/d6_dhcpc.c. The issue is tied to incorrect heap allocation calculations in option_to_env(), enabling memory corruption from a crafted DHCPv6 response.

Likely exposure

Highest exposure is embedded or Linux systems running BusyBox udhcpc6 and accepting DHCPv6 responses from local network segments. Downstream package impact is not fully described in the bundle, so product-specific exposure requires vendor inventory.

Exploitation context

The CVSS vector is adjacent network, low complexity, no privileges, and no user interaction. The bundle includes a public technical/exploit reference, but KEV is false and no cited source confirms active exploitation in the wild.

Researcher notes

Focus review on BusyBox udhcpc6 DNS_SERVERS option parsing and downstream builds derived before the patch. Evidence supports memory corruption from malformed DHCPv6 responses; exact exploit reliability and affected downstream product matrix are not established in the provided bundle.

Mitigation direction

  • Update BusyBox to a build containing commit 42202bfb1e6ac51fa995beda8be4d7b654aeee2a.
  • Review whether commit d368f3f7836d1c2484c8f839316e5c93e76d4409 is also required by your vendor.
  • Apply vendor-fixed packages, including Red Hat guidance where applicable.
  • If DHCPv6 is unnecessary, follow vendor guidance to disable the vulnerable client path.
  • Limit exposure to untrusted local network DHCPv6 responses where operationally feasible.

Validation and detection

  • Inventory systems and firmware images that include BusyBox udhcpc6.
  • Confirm BusyBox source or package builds include the referenced patch commit.
  • Check whether affected devices use DHCPv6 on reachable local network segments.
  • Review vendor advisories for exact downstream package status and fixed versions.
  • Prioritize embedded systems lacking modern heap hardening.
Prepared
Confidence
medium
Sources
11

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-122: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cwe · low confidence lookup

CWE-131: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

Execution behavior lookup

The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2026-29004 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
8.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

3CVSS vectors
5Timeline events
2ADP providers
10Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

CVSS vector scores

3 official scores

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
8.8CVSS 3.1HighCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H2.85.9redhat-SADP
8.1CVSS 3.1HighCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H2.85.2VulnCheck
7.2CVSS 4.0HighCVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:NVulnCheck

Vulnerability scoring details

Base CVSS 4.0 score

7.2High
CVSS 4.0 vector shape for CVE-2026-29004Attack VectorAttack ComplexityAttack RequirementsPrivileges RequiredUser InteractionVS ConfidentialityVS IntegrityVS AvailabilitySS ConfidentialitySS IntegritySS Availability

Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Attack Requirements
NonePresent
Privileges Required
NoneLowHigh
User Interaction
NonePassiveActive
VS Confidentiality
HighLowNone
VS Integrity
HighLowNone
VS Availability
HighLowNone
SS Confidentiality
HighLowNone
SS Integrity
HighLowNone
SS Availability
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. ADP timelineredhat-SADP

    Made public.

  3. CVE publishedCVE Program

    The CVE record was published.

  4. ADP timelineredhat-SADP

    Reported to Red Hat.

  5. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
redhat-SADPBusyBox: BusyBox: Arbitrary Code Execution via DHCPv6 Client Heap Buffer Overflow
other:Red Hat severity ratingcvssV3_1
  • 2026-05-04T19:03:24.638Z: Reported to Red Hat.
  • 2026-05-04T18:05:18.962Z: Made public.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
vda-linuxbusybox_mirror0affected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.