PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-2147 Canonical CVE debrief

CVE-2016-2147 is a network-reachable denial-of-service flaw in BusyBox udhcpc. A malformed RFC1035-encoded domain name can trigger an integer overflow and out-of-bounds heap write, leading to a crash. NVD rates it HIGH (CVSS 7.5) and maps exposure to BusyBox plus downstream Debian and Ubuntu builds listed in the record.

Vendor
Canonical
Product
Unknown
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-09
Original CVE updated
2026-05-13
Advisory published
2017-02-09
Advisory updated
2026-05-13

Who should care

Operators of BusyBox-based embedded Linux systems, appliances, and distro packages that include udhcpc, especially downstream Debian and Ubuntu deployments listed in NVD.

Technical summary

The issue is tracked as CWE-190 (integer overflow) with CVSS v3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The source corpus describes BusyBox versions before 1.25.0 as affected; NVD's CPE data also marks BusyBox through 1.24.2 and downstream Debian 8/9 and Ubuntu 14.04 ESM, 16.04 LTS, 18.04 LTS, and 18.10.

Defensive priority

High

Recommended defensive actions

  • Upgrade BusyBox to a release at or above 1.25.0, or apply the vendor-fixed package provided by your distribution.
  • Check whether udhcpc is present in firmware, containers, or appliance images and prioritize those that receive DHCP service on untrusted networks.
  • Use the BusyBox vendor advisory and downstream distro security notices to confirm patched package versions.
  • Validate remediation across all impacted images and rebuild any derived firmware or OS images that embed BusyBox.

Evidence notes

Supported by the CVE description, which cites an integer overflow in BusyBox udhcpc before 1.25.0 caused by a malformed RFC1035-encoded domain name and resulting in an out-of-bounds heap write. NVD lists CVSS 3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, CWE-190, and vulnerable CPEs for BusyBox plus Debian 8/9 and Ubuntu 14.04 ESM/16.04 LTS/18.04 LTS/18.10. The supplied record includes a BusyBox vendor advisory reference and the official CVE/NVD entries.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-2147 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-2147

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-2147 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-2147

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.