CVE-2026-88835

CVE-2026-88835 published: BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read.

View full NVD advisory → ← Back to CVE watch