Bug 2539987 (CVE-2026-88841)

Summary: CVE-2026-88841 busybox: busybox: dpkg write_status_file() stale cursor causes out-of-bounds read and status file corruption
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
BusyBox dpkg write_status_file() does not reset a stale field cursor between package stanzas, causing out-of-bounds reads and status file corruption when removing multiple packages.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-24 09:04:25 UTC
A vulnerability was found in the BusyBox dpkg implementation (archival/dpkg.c). The write_status_file() function does not reset the field_start cursor between package stanzas. When two packages are removed in a single invocation and the first stanza is larger than the second, the stale cursor causes an out-of-bounds read and silent corruption of the dpkg status file.

Upstream fix commits: f5a4a02a1, d5cc94063.
Reporter: Shubham Raj, Causal Security.
PSIRT Ticket: PSIRTSUPT-23314.