
Upwind Security MDR@UpwindMDR
🚨High - BusyBox TLS ClientKeyExchange Heap Buffer Overflow (CVE-2026-88830) BusyBox’s TLS Montgomery reduction buffer allocation has a unit confusion bug that mis-sizes a heap buffer. A remote attacker can trigger a pre-auth heap overflow by sending a crafted ClientKeyExchange during the handshake, causing a crash/DoS with high availability impact. 👉Affected: busybox (versions TBD)
0000050
305 followersView on X
