CVE-2026-29004 HIGH

CVE-2026-29004: BusyBox DHCPv6 Client Heap Buffer Overflow via DNS_SERVERS

Vendor Vda-Linux
Product busybox_mirror
Weakness CWE-122
Published May 4, 2026
Last update June 30, 2026

CVSS base score

7.2/10
Attack vector Adjacent
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhcpc.c that allows network-adjacent attackers to trigger memory corruption by sending a crafted DHCPv6 response with a malformed D6_OPT_DNS_SERVERS option. Attackers can exploit incorrect heap buffer allocation calculations in the option_to_env() function to cause denial of service or achieve arbitrary code execution on embedded systems without heap hardening.

Key dates

02Disclosure timeline

May 4, 2026 CVE published
June 30, 2026 Record updated