Files
buildroot/package/busybox/0019-CVE-2026-29004-01.patch
Thomas Perale via buildroot 3a5af1b3c0 package/busybox: patch CVE-2026-29004
Thanks to the OpenEmbedded community for the patches. This fixes the
following vulnerability:

- CVE-2026-29004:
    BusyBox before commit 42202bf contains a heap buffer overflow
    vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option
    handler in networking/udhcp/d6_dhcpc.c that allows network-adjacent
    attackers to trigger memory corruption by sending a crafted DHCPv6
    response with a malformed D6_OPT_DNS_SERVERS option. Attackers can
    exploit incorrect heap buffer allocation calculations in the
    option_to_env() function to cause denial of service or achieve
    arbitrary code execution on embedded systems without heap hardening.
    https://www.cve.org/CVERecord?id=CVE-2026-29004

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
(alternative to commit 5a27004cff)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
2026-08-21 17:04:09 +02:00

40 lines
1.2 KiB
Diff

From d9a718cc17535c31d38f31fccb904a30e823166d Mon Sep 17 00:00:00 2001
From: Denys Vlasenko <vda.linux@googlemail.com>
Date: Thu, 12 Mar 2026 07:25:38 +0100
Subject: [PATCH] udhcpc6: fix buffer overflow
Signed-off-by: Denys Vlasenko <vda.linux@googlemail.com>
Upstream: https://github.com/vda-linux/busybox_mirror/commit/42202bfb1e6ac51fa995beda8be4d7b654aeee2a
CVE: CVE-2026-29004
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
---
networking/udhcp/d6_dhcpc.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/networking/udhcp/d6_dhcpc.c b/networking/udhcp/d6_dhcpc.c
index 79cef1999..d13b05829 100644
--- a/networking/udhcp/d6_dhcpc.c
+++ b/networking/udhcp/d6_dhcpc.c
@@ -351,15 +351,15 @@ static void option_to_env(const uint8_t *option, const uint8_t *option_end)
addrs = option[3] >> 4;
/* Setup environment variable */
- *new_env() = dlist = xmalloc(4 + addrs * 40 - 1);
+ *new_env() = dlist = xmalloc(4 + addrs * 40 + 1);
dlist = stpcpy(dlist, "dns=");
option_offset = 0;
- while (addrs--) {
+ while (addrs-- != 0) {
sprint_nip6(dlist, option + 4 + option_offset);
dlist += 39;
option_offset += 16;
- if (addrs)
+ if (addrs != 0)
*dlist++ = ' ';
}
--
2.34.1