{"id":"CVE-2026-88835","title":"BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read.","summary":"BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read.","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","cwe":["CWE-125"],"vendor":"Red Hat","product":"busybox","affected":["busybox (all versions)"],"published":"2026-09-23","updated":"2026-09-23","sourceUpdated":"2026-09-23T19:40:10.000","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-88835","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-88835","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2531349","label":"secalert@redhat.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-23T18:29:33.146Z","slug":"CVE-2026-88835","body":"## Overview\n\nBusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}