Package
busybox-full
Component
busybox-full
Latest update
Fixed version
1.38.0-r1
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
1.38.0-r1Impact
busybox 1.38.0-r1 applies CVE-2026-38752.patch (busybox ML patch, https://lists.busybox.net/pipermail/busybox/2026-June/092351.html), which adds a recursion depth limit to the awk expression evaluator, preventing process stack exhaustion via crafted AWK scripts. See: https://github.com/wolfi-dev/os/blob/main/busybox/CVE-2026-38752.patch. Manual fixed event: the fix is a source patch at an unchanged upstream version (1.38.0), and no scanner detection exists for this CVE (its NVD CPE pins a git-snapshot version), so both the advisory and the fixed event are created manually.