Security Advisory
CVE-2026-38755
2.9
LOW
Vulnerability Description
A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
Published Date
July 15, 2026
Official Source
NIST NVD Advisory