Microsoft Security Response Center guidance
Release Notes
Vulnerability intelligence
CVE-2026-88839 and is rated Medium severity with a CVSS score of 6.7. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Release Notes
BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers.