CVE-2026-88839: Red Hat Hardened Images

Medium severity, CVSS 6.7. EPSS: 0.1% chance of exploitation in the next 30 days.

BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers.

Affected products

  • Red Hat Red Hat Hardened Images: before 1.37.0-9.1.hum1 (fixed in 1.37.0-9.1.hum1)

Published 2026-09-23. Last modified 2026-09-25.