CVE-2026-29004: BusyBox DHCPv6 Client Heap Buffer Overflow via DNS_SERVERS
BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhcpc.c that allows network-adjacent attackers to trigger memory corruption by sending a crafted DHCPv6 response with a malformed D6_OPT_DNS_SERVERS option. Attackers can exploit incorrect heap buffer allocation calculations in the option_to_env() function to cause denial of service or achieve arbitrary code execution on embedded systems without heap hardening.
Security readout for executives and security teams
Plain-English summary
This vulnerability affects BusyBox’s DHCPv6 client, common in embedded Linux systems. A nearby attacker on the same network could send a malformed DHCPv6 response that corrupts memory. Reported impact includes denial of service and potential code execution, especially on systems without heap hardening.
Executive priority
Treat this as a high-priority infrastructure and embedded-device issue. It is not described as internet-routable, but local network compromise paths can matter in branch, IoT, OT, and appliance environments. Patch or validate vendor status promptly.
Technical view
BusyBox before commit 42202bf has a heap buffer overflow in udhcpc6 handling of D6_OPT_DNS_SERVERS in networking/udhcp/d6_dhcpc.c. The issue is tied to incorrect heap allocation calculations in option_to_env(), enabling memory corruption from a crafted DHCPv6 response.
Likely exposure
Highest exposure is embedded or Linux systems running BusyBox udhcpc6 and accepting DHCPv6 responses from local network segments. Downstream package impact is not fully described in the bundle, so product-specific exposure requires vendor inventory.
Exploitation context
The CVSS vector is adjacent network, low complexity, no privileges, and no user interaction. The bundle includes a public technical/exploit reference, but KEV is false and no cited source confirms active exploitation in the wild.
Researcher notes
Focus review on BusyBox udhcpc6 DNS_SERVERS option parsing and downstream builds derived before the patch. Evidence supports memory corruption from malformed DHCPv6 responses; exact exploit reliability and affected downstream product matrix are not established in the provided bundle.
Mitigation direction
Update BusyBox to a build containing commit 42202bfb1e6ac51fa995beda8be4d7b654aeee2a.
Review whether commit d368f3f7836d1c2484c8f839316e5c93e76d4409 is also required by your vendor.
Apply vendor-fixed packages, including Red Hat guidance where applicable.
If DHCPv6 is unnecessary, follow vendor guidance to disable the vulnerable client path.
Limit exposure to untrusted local network DHCPv6 responses where operationally feasible.
Validation and detection
Inventory systems and firmware images that include BusyBox udhcpc6.
Confirm BusyBox source or package builds include the referenced patch commit.
Check whether affected devices use DHCPv6 on reachable local network segments.
Review vendor advisories for exact downstream package status and fixed versions.
Prioritize embedded systems lacking modern heap hardening.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-122: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.