THREATOPS
THREAT OPSThreat News › BusyBox dpkg applet: OS command injection

BusyBox dpkg applet: OS command injection

lowoss_secPublished 2026-08-24

<p>Posted by Solar Designer on Aug 23</p>Hi,<br /> <br /> Anmol Bakshi brought the below with original Subject line saying<br /> &quot;BusyBox dpkg applet: OS command injection -&gt; root RCE (CWE-78)&quot; to<br /> linux-distros on July 13. We quickly determined that no privilege<br /> boundary is crossed, so the coordinated disclosure request was<br /> withdrawn. However, we cannot just withdr

Original source: https://seclists.org/oss-sec/2026/q3/556