Your message dated Sun, 26 Jul 2026 06:18:45 +0000
with message-id <[email protected]>
and subject line Bug#1142472: fixed in busybox 1:1.38.0-3
has caused the Debian Bug report #1142472,
regarding busybox: CVE-2026-38752 CVE-2026-38753 CVE-2026-38754 CVE-2026-38755
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1142472: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142472
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: busybox
Version: 1:1.38.0-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerabilities were published for busybox.
CVE-2026-38752[0]:
| A stack overflow in the evaluate() function (editors/awk.c) of
| BusyBox commit 371fe9 allows attackers to cause a Denial of Service
| (DoS) via supplying a crafted AWK script.
CVE-2026-38753[1]:
| A use-after-free in the awk_sub() function (editors/awk.c) of
| Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS)
| via supplying a crafted AWK script.
CVE-2026-38754[2]:
| A heap overflow in the ifsbreakup() function (shell/ash.c) of
| Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS)
| via supplying a crafted input.
CVE-2026-38755[3]:
| A heap overflow in the evalcommand() function (shell/ash.c) of
| Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS)
| via supplying a crafted input.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-38752
https://www.cve.org/CVERecord?id=CVE-2026-38752
[1] https://security-tracker.debian.org/tracker/CVE-2026-38753
https://www.cve.org/CVERecord?id=CVE-2026-38753
[2] https://security-tracker.debian.org/tracker/CVE-2026-38754
https://www.cve.org/CVERecord?id=CVE-2026-38754
[3] https://security-tracker.debian.org/tracker/CVE-2026-38755
https://www.cve.org/CVERecord?id=CVE-2026-38755
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: busybox
Source-Version: 1:1.38.0-3
Done: Michael Tokarev <[email protected]>
We believe that the bug you reported is fixed in the latest version of
busybox, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Michael Tokarev <[email protected]> (supplier of updated busybox package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sun, 26 Jul 2026 08:53:18 +0300
Source: busybox
Architecture: source
Version: 1:1.38.0-3
Distribution: unstable
Urgency: medium
Maintainer: Debian Install System Team <[email protected]>
Changed-By: Michael Tokarev <[email protected]>
Closes: 1142472
Changes:
busybox (1:1.38.0-3) unstable; urgency=medium
.
* fix 4 (minor) security issues (Closes: #1142472):
- ash-fix-out-of-bounds-read-in-ifsbreakup-CVE-2026-38754.patch
- ash-fix-stack-overflow-in-evalfun-CVE-2026-38755.patch
- awk-fix-stack-overflow-in-evaluate-CVE-2026-38752.patch
- awk-fix-use-after-free-in-awk_sub-CVE-2026-38753.patch
Checksums-Sha1:
f94c4b06a65a770d78de4691871f06eea9e9c861 2529 busybox_1.38.0-3.dsc
6ef8d237a825ed0a61fee4f68d42b19d4d3aca5d 2695723 busybox_1.38.0.orig.tar.bz2
101b46347e888a5603a7130d53534178aa04eeae 121 busybox_1.38.0.orig.tar.bz2.asc
8b89e7a76c911ba9176abccd48df758ed7d23f49 66644 busybox_1.38.0-3.debian.tar.xz
d6266738a7d5c051da17abb8e4988e08d44b9b7d 5446 busybox_1.38.0-3_source.buildinfo
Checksums-Sha256:
7c3b52b1dd3792b57681b26adfdaefab77de25f1d453e8ffb78187624a3bc57c 2529
busybox_1.38.0-3.dsc
34f9ea6ff8636f2c9241153b9114eefa9e65674a45318ae1ef95bb5f31c53bb2 2695723
busybox_1.38.0.orig.tar.bz2
a496ee9653bc7faa0fd159f171b257bb6df612018fd8e50be83d956c16107a5b 121
busybox_1.38.0.orig.tar.bz2.asc
9493090e7456abb7707a356ab71a810065b555fdeddc6f71d4dd1dc09ebc342f 66644
busybox_1.38.0-3.debian.tar.xz
c928cd517693833e572b3fa1a43d10da310f084139ad3f6447749976828a62a1 5446
busybox_1.38.0-3_source.buildinfo
Files:
8daef02510b1aab0538bedbd2ac16818 2529 utils optional busybox_1.38.0-3.dsc
2a76df79da776a165bf85257403c97bc 2695723 utils optional
busybox_1.38.0.orig.tar.bz2
10550c8523d66769aa17f6a0e22d35a1 121 utils optional
busybox_1.38.0.orig.tar.bz2.asc
0cd800b73a8a0b09dfc59b9d1331383a 66644 utils optional
busybox_1.38.0-3.debian.tar.xz
c5c922f741cf252b95217336d90e91de 5446 utils optional
busybox_1.38.0-3_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEZKoqtTHVaQM2a/75gqpKJDselHgFAmplpW8ACgkQgqpKJDse
lHi7rQ//SVK7D3+DiboD30LtdtOvX+4uT7nHFRixrmvj5ZuSb5I4YLKAfBCvG1Kz
o8rfpsZMroLZb4x7GYsMR+nPFjp5gz4Ug1yfg0eJzL/ds0C4TaRC/e2Y4YL5kC+8
jH/qaQNFmJ2EOWTbPejtDbFXrEY/TV+xy2MlKS/EDjLQTWQIEzkBzytDjYSm9tPg
Z5A/6//ySQ0esfKUWBHfnOp1UcoWnO9Lnu+pQL4fVot55SZwyoVN9ynqAViVQ48V
X3OUeQWobqksOaq9QsE/++GKmb/btds0RTtCK/+LOSfXO4slyHPjSLXo0LWkfAG2
HW2dJrzVHxode3tv3FNQ+g/p1/zQSDLB4V5WRXz6m/JUU1KDOMPx1LtuUhcxJY5i
QcBganvTL62Mo3PS/dA5AwOczHiR5rmkpvJ6U36IwxlUsxEqWCdDX9WvYELsfM3J
cVYxA9NBt4aCIrzJqnry9NzE4JQxOu7/k4EH+BsJ1sSTfECckWJI262TZqxwHLG8
+A12g7VvdaOysrQSZBwnDk3dNWoSWGVsglxEocaqqVM10ZIhZCORNMRPG/fSPCGr
/ndfENwtW3cqvVevnAymZL0zOTZn7BB9BETaLxZJV0GwNFjfCpZLfD7gREeXGeLF
zPGGATsmJkmDF7bwYS3EBJoIcg1IN63fZpA8h+ynqMKpNKMmsCg=
=C587
-----END PGP SIGNATURE-----
pgpdpt3IDmM7Z.pgp
Description: PGP signature
--- End Message ---