SUSE and openSUSE BusyBox Vulnerabilities Addressed in Recent Updates

SUSE and openSUSE BusyBox Vulnerabilities Addressed in Recent Updates

First seen 1 Sep 2026, 22:29 UTC Linuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

On September 1, 2026, SUSE and openSUSE released updates addressing multiple vulnerabilities in BusyBox. The updates fix five critical issues, including CVE-2023-42366, a heap buffer overflow, and CVEs from 2026-38752 to 2026-38755, which include stack buffer overflows and use-after-free vulnerabilities. These vulnerabilities affect the BusyBox package, which is widely used in various Linux distributions. Attackers could exploit these vulnerabilities to execute arbitrary code or cause denial-of-service conditions. Users are advised to apply the patches immediately using recommended installation methods such as 'zypper patch'. The vulnerabilities were disclosed on July 15, 2026, and are rated as moderate in severity. The updates are crucial for maintaining system integrity and security.

Key Points: • Five vulnerabilities in BusyBox have been patched, including critical heap and stack overflows. • Affected CVEs include CVE-2023-42366 and CVEs from 2026-38752 to 2026-38755. • Users must apply patches immediately to mitigate potential exploitation risks.

Timeline

2023-11-27
CVE-2023-42366 published
Heap buffer overflow vulnerability in BusyBox's `next_token` function disclosed.
Linuxsecurity
2026-07-15
Multiple CVEs published
CVE-2026-38752, CVE-2026-38753, CVE-2026-38754, and CVE-2026-38755 disclosed, affecting BusyBox.
Linuxsecurity
2026-07-15
CVE-2026-38755 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-15
CVE-2026-38752 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-15
CVE-2026-38754 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-15
CVE-2026-38753 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
Updates released for BusyBox
SUSE and openSUSE released patches addressing multiple vulnerabilities in BusyBox.
Linuxsecurity