CRITICAL🇵🇱 Wersja polska

CVE-2025-69808

CVSS 9.1v3.1pub. 2026-03-16upd. 2026-04-27

An out-of-bounds memory access (OOB) in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to access sensitive information and cause a Denial of Service (DoS) via supplying a crafted packet.

🤖 AI Analysis
How it works

An attacker sends a specially crafted network packet to the vulnerable Bareiron instance. The application improperly handles memory buffer boundaries (CWE-125 — out-of-bounds read), resulting in data being read from outside the allocated memory area. The exploit does not require any authentication or user interaction, and the attack can be performed remotely over the network.

Impact

An attacker can gain unauthorized access to sensitive data stored in the process memory and cause an application crash (Denial of Service). High impact on confidentiality and availability of the system with no impact on integrity.

Mitigation & patch

Apply patches available from the vendor according to the references. It is recommended to monitor the project repository at https://github.com/p2r3/bareiron/ to obtain an updated version of the code. Until the patch is applied, consider restricting network access to Bareiron instances at the firewall level.

Who is affected

P2R3 Bareiron — commit 8e4d40

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
  • P2r3 Bareiron

    APP
    P2R3
    2025-09-16
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth BypassDoSMemory
CWE
References

Related vulnerabilities

CVE-2025-69809CRITICAL9.8PL ✓same product

Write-What-Where w P2R3 Bareiron — zdalne wykonanie kodu bez uwierzytelnienia

CVE-2025-69806HIGH7.5same product

p2r3 bareiron commit: 8e4d4020d contains an Out-of-bounds Read, which allows unauthenticated remote attackers ...

CVE-2025-69807HIGH7.5same product

p2r3 Bareiron commit: 8e4d4020d is vulnerable to Buffer Overflow, which allows unauthenticated remote attacker...