{"id":"SUSE-SU-2026:23446-1","summary":"Security update for busybox","details":"This update for busybox fixes the following issues:\n\n- CVE-2023-42366: heap buffer overflow in the `next_token` function of `editors/awk.c` (bsc#1217586).\n- CVE-2026-38752: stack buffer overflow in the `evaluate()` function of `editors/awk.c` (bsc#1271544).\n- CVE-2026-38753: use-after-free in the `awk_sub()` function of `editors/awk.c` (bsc#1271545).\n- CVE-2026-38754: heap buffer overflow in `ifsbreakup()` function of `shell/ash.c` (bsc#1271547).\n- CVE-2026-38755: heap buffer overflow in `evalcommand()` function of `shell/ash.c` (bsc#1271548).\n","modified":"2026-09-14T18:23:33.140530806Z","published":"2026-09-02T09:40:31Z","related":["CVE-2023-42366","CVE-2026-38752","CVE-2026-38753","CVE-2026-38754","CVE-2026-38755"],"upstream":["CVE-2023-42366","CVE-2026-38752","CVE-2026-38753","CVE-2026-38754","CVE-2026-38755"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202623446-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1217586"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271544"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271545"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271547"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271548"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-42366"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-38752"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-38753"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-38754"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-38755"}],"affected":[{"package":{"name":"busybox","ecosystem":"SUSE:Linux Micro 6.0","purl":"pkg:rpm/suse/busybox&distro=SUSE%20Linux%20Micro%206.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.36.1-5.1"}]}],"ecosystem_specific":{"binaries":[{"busybox":"1.36.1-5.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23446-1.json"}}],"schema_version":"1.9.0"}