漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
barebox Out-of-Bounds Read in DHCP Option Parsing
Vulnerability Description
barebox prior to version 2026.04.0 contains an out-of-bounds read vulnerability in DHCP option parsing within the dhcp_message_type() function that fails to verify the options pointer remains within received packet bounds. An attacker on the same broadcast domain can send a crafted DHCP Offer or ACK packet without a proper 0xff end marker to cause the parser to read past valid packet data and potentially crash the system.
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
跨界内存读
Vulnerability Title
Barebox 缓冲区错误漏洞
Vulnerability Description
Barebox是Barebox开源的一个多功能且灵活的引导加载程序。 barebox 2026.04.0之前版本存在缓冲区错误漏洞,该漏洞源于DHCP选项解析中dhcp_message_type()函数未验证选项指针是否在接收数据包边界内,可能导致攻击者发送特制DHCP Offer或ACK数据包导致越界读取并可能使系统崩溃。
CVSS Information
N/A
Vulnerability Type
N/A