A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
https://lists.busybox.net/pipermail/busybox/2026-June/092360.html
https://lists.busybox.net/pipermail/busybox/2026-June/092353.html