Bug 2531344 (CVE-2026-88830) - CVE-2026-88830 busybox: busybox: TLS Montgomery reduction allocates bytes instead of digits, causing a pre-auth heap buffer overflow
Summary: CVE-2026-88830 busybox: busybox: TLS Montgomery reduction allocates bytes ins...
Keywords:
Status: NEW
Alias: CVE-2026-88830
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2540205
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-10 09:45 UTC by OSIDB Bzimport
Modified: 2026-09-24 15:28 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-10 09:45:36 UTC
A vulnerability was found in the BusyBox TLS implementation (networking/tls_pstm_montgomery_reduce.c). A unit confusion error exists in the buffer allocation for the Montgomery reduction operation. The code calls xzalloc(2*pa+1) where pa is measured in pstm_digit units (4 or 8 bytes each), but the allocation treats this value as a byte count. This results in an allocation approximately 4x to 8x smaller than required.

When a TLS client sends a crafted ClientKeyExchange message with an all-zeros payload, the RSA decryption path triggers the Montgomery reduction, which writes digit-sized elements beyond the allocated buffer boundary. This constitutes a pre-authentication out-of-bounds heap write.

The confirmed impact is a pre-authentication denial of service (crash). While the heap buffer overflow is theoretically exploitable for remote code execution, this was not demonstrated. On Fedora, system-level mitigations including ASLR, PIE, full RELRO, and SELinux confinement make practical code execution extremely unlikely.


Note You need to log in before you can comment on or make changes to this bug.