An out-of-bounds memory access (OOB) in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to access sensitive information and cause a Denial of Service (DoS) via supplying a crafted packet.
An attacker sends a specially crafted network packet to the vulnerable Bareiron instance. The application improperly handles memory buffer boundaries (CWE-125 — out-of-bounds read), resulting in data being read from outside the allocated memory area. The exploit does not require any authentication or user interaction, and the attack can be performed remotely over the network.
An attacker can gain unauthorized access to sensitive data stored in the process memory and cause an application crash (Denial of Service). High impact on confidentiality and availability of the system with no impact on integrity.
Apply patches available from the vendor according to the references. It is recommended to monitor the project repository at https://github.com/p2r3/bareiron/ to obtain an updated version of the code. Until the patch is applied, consider restricting network access to Bareiron instances at the firewall level.
P2R3 Bareiron — commit 8e4d40
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HP2r3 Bareiron
APPP2R32025-09-16
Related vulnerabilities
Write-What-Where w P2R3 Bareiron — zdalne wykonanie kodu bez uwierzytelnienia
p2r3 bareiron commit: 8e4d4020d contains an Out-of-bounds Read, which allows unauthenticated remote attackers ...
p2r3 Bareiron commit: 8e4d4020d is vulnerable to Buffer Overflow, which allows unauthenticated remote attacker...