Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-busybox | Oct 1, 2024 | Feb 9, 2017 | |
| Debian | debian-upgrade-busybox | Feb 20, 2019 | Feb 9, 2017 | |
| F5 Big Ip | f5-bigip-upgrade-latest | Jun 17, 2026 | Oct 14, 2025 | |
| Gentoo Linux | gentoo-linux-upgrade-sys-apps-busybox | Oct 30, 2017 | Feb 9, 2017 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Mar 10, 2016 | |
| Suse | — | suse-upgrade-busyboxsuse-upgrade-busybox-static | Jan 21, 2022 | Feb 9, 2017 |
| Ubuntu | ubuntu-upgrade-busyboxubuntu-upgrade-busybox-initramfsubuntu-upgrade-busybox-staticubuntu-upgrade-udhcpcubuntu-upgrade-udhcpd | Apr 10, 2019 | Feb 9, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub