Package
busybox
Component
busybox
Latest update
Fixed version
1.38.0-r0
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
1.38.0-r0Impact
busybox 1.38.0-r0 applies CVE-2026-38753.patch (busybox ML patch, https://lists.busybox.net/pipermail/busybox/2026-June/092352.html), which copies the replacement string in awk_sub() before regex evaluation, fixing the use-after-free. See: https://github.com/wolfi-dev/os/blob/main/busybox/CVE-2026-38753.patch. Manual fixed event: the fix is a source patch at an unchanged upstream version (1.38.0), so it is invisible to version-based scanner metadata and automation will never emit the fixed event.
Status