{"cve":"CVE-2026-88830","mitre":{"cpes":["cpe:/a:redhat:hummingbird:1"],"created":"2026-09-23T17:04:57.011000+00:00","description":"A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow when processing a crafted ClientKeyExchange message.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":7.5,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"cvssV4_0":{}},"mitre_repo_path":"cves/2026/88xxx/CVE-2026-88830.json","references":["https://access.redhat.com/security/cve/CVE-2026-88830","https://bugzilla.redhat.com/show_bug.cgi?id=2531344"],"title":"Busybox: busybox: tls montgomery reduction allocates bytes instead of digits, causing a pre-auth heap buffer overflow","updated":"2026-09-23T17:04:57.011000+00:00","vendors":["redhat","redhat$PRODUCT$hummingbird"],"weaknesses":["CWE-131"]},"opencve":{"changes":[{"created":"2026-09-23T17:15:00+00:00","data":[{"details":{"new":"A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow when processing a crafted ClientKeyExchange message.","old":null},"type":"description"},{"details":{"new":"Busybox: busybox: tls montgomery reduction allocates bytes instead of digits, causing a pre-auth heap buffer overflow","old":null},"type":"title"},{"details":["redhat","redhat$PRODUCT$hummingbird"],"type":"first_time"},{"details":{"added":["CWE-131"],"removed":[]},"type":"weaknesses"},{"details":{"added":["cpe:/a:redhat:hummingbird:1"],"removed":[]},"type":"cpes"},{"details":{"added":["redhat","redhat$PRODUCT$hummingbird"],"removed":[]},"type":"vendors"},{"details":{"added":["https://access.redhat.com/security/cve/CVE-2026-88830","https://bugzilla.redhat.com/show_bug.cgi?id=2531344"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":7.5,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"8ff7eceb-222f-4008-a56c-08cabedf4e33"}],"cpes":{"data":["cpe:/a:redhat:hummingbird:1"],"providers":["mitre"]},"created":{"data":"2026-09-23T17:04:57.011000+00:00","provider":"mitre"},"description":{"data":"A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow when processing a crafted ClientKeyExchange message.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":7.5,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{},"provider":null},"kev":{"data":{},"provider":null},"ssvc":{"data":{},"provider":null},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://access.redhat.com/security/cve/CVE-2026-88830","https://bugzilla.redhat.com/show_bug.cgi?id=2531344"],"providers":["mitre"]},"title":{"data":"Busybox: busybox: tls montgomery reduction allocates bytes instead of digits, causing a pre-auth heap buffer overflow","provider":"mitre"},"updated":{"data":"2026-09-23T17:04:57.011000+00:00","provider":"mitre"},"vendors":{"data":["redhat","redhat$PRODUCT$hummingbird"],"providers":["mitre"]},"weaknesses":{"data":["CWE-131"],"providers":["mitre"]}}}