Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade busybox | Oct 1, 2024 | Feb 9, 2017 |
| Debian | — | Upgrade busybox | Feb 20, 2019 | Feb 9, 2017 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Oct 14, 2025 |
| Gentoo Linux | — | Upgrade sys-apps/busybox. | Oct 30, 2017 | Feb 9, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 10, 2016 |
| Suse | — | Upgrade busybox-staticUpgrade busybox | Jan 21, 2022 | Feb 9, 2017 |
| Ubuntu | — | Upgrade udhcpcUpgrade busybox-initramfsUpgrade busybox-staticUpgrade udhcpdUpgrade busybox | Apr 10, 2019 | Feb 9, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub