PatchSiren cyber security CVE debrief
CVE-2016-2147 Canonical CVE debrief
CVE-2016-2147 is a network-reachable denial-of-service flaw in BusyBox udhcpc. A malformed RFC1035-encoded domain name can trigger an integer overflow and out-of-bounds heap write, leading to a crash. NVD rates it HIGH (CVSS 7.5) and maps exposure to BusyBox plus downstream Debian and Ubuntu builds listed in the record.
- Vendor
- Canonical
- Product
- Unknown
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-09
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-09
- Advisory updated
- 2026-05-13
Who should care
Operators of BusyBox-based embedded Linux systems, appliances, and distro packages that include udhcpc, especially downstream Debian and Ubuntu deployments listed in NVD.
Technical summary
The issue is tracked as CWE-190 (integer overflow) with CVSS v3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The source corpus describes BusyBox versions before 1.25.0 as affected; NVD's CPE data also marks BusyBox through 1.24.2 and downstream Debian 8/9 and Ubuntu 14.04 ESM, 16.04 LTS, 18.04 LTS, and 18.10.
Defensive priority
High
Recommended defensive actions
- Upgrade BusyBox to a release at or above 1.25.0, or apply the vendor-fixed package provided by your distribution.
- Check whether udhcpc is present in firmware, containers, or appliance images and prioritize those that receive DHCP service on untrusted networks.
- Use the BusyBox vendor advisory and downstream distro security notices to confirm patched package versions.
- Validate remediation across all impacted images and rebuild any derived firmware or OS images that embed BusyBox.
Evidence notes
Supported by the CVE description, which cites an integer overflow in BusyBox udhcpc before 1.25.0 caused by a malformed RFC1035-encoded domain name and resulting in an out-of-bounds heap write. NVD lists CVSS 3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, CWE-190, and vulnerable CPEs for BusyBox plus Debian 8/9 and Ubuntu 14.04 ESM/16.04 LTS/18.04 LTS/18.10. The supplied record includes a BusyBox vendor advisory reference and the official CVE/NVD entries.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-2147 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-2147
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-2147 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-2147
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://busybox.net/news.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.