OESA-2026-3686

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-3686
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-3686.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-3686
Upstream
Published
2026-09-05T15:03:55Z
Modified
2026-09-05T15:16:35.022013947Z
Severity
  • 3.3 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
busybox security update
Details

The Swiss Army Knife of Embedded Linux

Security Fix(es):

A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of the file networking/wget.c of the component FEATUREWGETTIMEOUT Handler. Such manipulation of the argument -T leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is 83a40bf7a93c8ac093d33ab452222dd5b9eb57ff. A patch should be applied to remediate this issue.(CVE-2026-76014)

Database specific
{
    "severity": "Low"
}
References

Affected packages

openEuler:20.03-LTS-SP4 / busybox

Package

Name
busybox
Purl
pkg:rpm/openEuler/busybox&distro=openEuler-20.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.31.1-36.oe2003sp4

Ecosystem specific

{
    "src": [
        "busybox-1.31.1-36.oe2003sp4.src.rpm"
    ],
    "x86_64": [
        "busybox-1.31.1-36.oe2003sp4.x86_64.rpm",
        "busybox-debuginfo-1.31.1-36.oe2003sp4.x86_64.rpm",
        "busybox-debugsource-1.31.1-36.oe2003sp4.x86_64.rpm",
        "busybox-help-1.31.1-36.oe2003sp4.x86_64.rpm",
        "busybox-petitboot-1.31.1-36.oe2003sp4.x86_64.rpm"
    ],
    "aarch64": [
        "busybox-1.31.1-36.oe2003sp4.aarch64.rpm",
        "busybox-debuginfo-1.31.1-36.oe2003sp4.aarch64.rpm",
        "busybox-debugsource-1.31.1-36.oe2003sp4.aarch64.rpm",
        "busybox-help-1.31.1-36.oe2003sp4.aarch64.rpm",
        "busybox-petitboot-1.31.1-36.oe2003sp4.aarch64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-3686.json"