Package
busybox
Component
busybox
Latest update
Fixed version
1.38.0-r0
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
1.38.0-r0Impact
busybox 1.38.0-r0 applies CVE-2026-38754.patch, upstream commit a448b6d5b21e5b21249391389b6f0551d9bea136 ("ash: fix out-of-bounds read in ifsbreakup()"), which restores IFS region cleanup on error unwind. See: https://github.com/wolfi-dev/os/blob/main/busybox/CVE-2026-38754.patch. Manual fixed event: the fix is a source patch at an unchanged upstream version (1.38.0), so it is invisible to version-based scanner metadata and automation will never emit the fixed event.
Status