shield
Security update for busybox
SUSE-SLE-Module-Basesystem-15-SP7-2026-3933
This update for busybox fixes the following issues: - CVE-2023-42366: heap buffer overflow in the `next_token` function of `editors/awk.c` (bsc#1217586). - CVE-2026-38752: stack buffer overflow in the `evaluate()` function of `editors/awk.c` (bsc#1271544). - CVE-2026-38753: use-after-free in the `awk_sub()` function of `editors/awk.c` (bsc#1271545). - CVE-2026-38754: heap buffer overflow in `ifsbreakup()` function of `shell/ash.c` (bsc#1271547). - CVE-2026-38755: heap buffer overflow in `evalcommand()` function of `shell/ash.c` (bsc#1271548).
-
Release DateSep 3 2026
-
ReferencesBugzilla: 1217586, 1271544, 1271545, 1271547, 1271548
CVEs: CVE-2023-42366, CVE-2026-38752, CVE-2026-38753, CVE-2026-38754, CVE-2026-38755 -
Typesecurity
-
Severitymoderate
cloud_download Downloads
Basesystem Module 15.7 s390x
-
Packagesbusybox
Minimalist variant of UNIX utilities linked in a single executablebusybox-static1.37.0-150700.18.21.1 lock rpm lock src
Static linked version of Busybox, a compact UNIX utility collection1.37.0-150700.18.21.1 lock rpm
Basesystem Module 15.7 ppc64le
-
Packagesbusybox
Minimalist variant of UNIX utilities linked in a single executablebusybox-static1.37.0-150700.18.21.1 lock rpm lock src
Static linked version of Busybox, a compact UNIX utility collection1.37.0-150700.18.21.1 lock rpm
Basesystem Module 15.7 aarch64
-
Packagesbusybox
Minimalist variant of UNIX utilities linked in a single executablebusybox-static1.37.0-150700.18.21.1 lock rpm lock src
Static linked version of Busybox, a compact UNIX utility collection1.37.0-150700.18.21.1 lock rpm
Basesystem Module 15.7 x86_64
-
Packagesbusybox
Minimalist variant of UNIX utilities linked in a single executablebusybox-static1.37.0-150700.18.21.1 lock rpm lock src
Static linked version of Busybox, a compact UNIX utility collection1.37.0-150700.18.21.1 lock rpm