Integer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cause a denial of service (crash) via a malformed RFC1035-encoded domain name, which triggers an out-of-bounds heap write.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade busybox | Oct 1, 2024 | Feb 9, 2017 |
| Debian | — | Upgrade busybox | Feb 20, 2019 | Feb 9, 2017 |
| Gentoo Linux | — | Upgrade sys-apps/busybox. | Oct 30, 2017 | Feb 9, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 10, 2016 |
| Suse | — | Upgrade busyboxUpgrade busybox-static | Jan 21, 2022 | Feb 9, 2017 |
| Ubuntu | — | Upgrade busybox-initramfsUpgrade busyboxUpgrade busybox-staticUpgrade udhcpdUpgrade udhcpc | Apr 10, 2019 | Feb 9, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub