CVE-2026-26157

EUVD-2026-7022
A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file overwrite, potentially enabling code execution through the modification of sensitive system files.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7 HIGH
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 34%
Debian logo
Debian Releases
Debian Product
Codename
busybox
bookworm
no-dsa
bullseye
postponed
bullseye (security)
vulnerable
forky
1:1.37.0-10.1
fixed
sid
1:1.37.0-10.1
fixed
trixie
no-dsa
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
busybox
suse enterprise desktop 15 SP7
1.37.0-150700.18.15.1
fixed
suse enterprise sap 15 SP5
1.37.0-150500.10.17.1
fixed
suse enterprise sap 15 SP6
1.37.0-150500.10.17.1
fixed
suse enterprise sap 15 SP7
1.37.0-150700.18.15.1
fixed
suse enterprise server 15 SP4
1.35.0-150400.3.14.1
fixed
suse enterprise server 15 SP5
1.37.0-150500.10.17.1
fixed
suse enterprise server 15 SP6
1.37.0-150500.10.17.1
fixed
suse enterprise server 15 SP7
1.37.0-150700.18.15.1
fixed
busybox-static
suse enterprise desktop 15 SP7
1.37.0-150700.18.15.1
fixed
suse enterprise sap 15 SP5
1.37.0-150500.10.17.1
fixed
suse enterprise sap 15 SP6
1.37.0-150500.10.17.1
fixed
suse enterprise sap 15 SP7
1.37.0-150700.18.15.1
fixed
suse enterprise server 15 SP4
1.35.0-150400.3.14.1
fixed
suse enterprise server 15 SP5
1.37.0-150500.10.17.1
fixed
suse enterprise server 15 SP6
1.37.0-150500.10.17.1
fixed
suse enterprise server 15 SP7
1.37.0-150700.18.15.1
fixed