{"id":"CVE-2026-34960","summary":"barebox Out-of-Bounds Read in DHCP Option Parsing","details":"barebox prior to version 2026.04.0 contains an out-of-bounds read vulnerability in DHCP option parsing within the dhcp_message_type() function that fails to verify the options pointer remains within received packet bounds. An attacker on the same broadcast domain can send a crafted DHCP Offer or ACK packet without a proper 0xff end marker to cause the parser to read past valid packet data and potentially crash the system.","modified":"2026-08-12T03:51:48.409490708Z","published":"2026-05-11T20:49:01.966Z","database_specific":{"cwe_ids":["CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34960.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34960.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34960"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/barebox-out-of-bounds-read-in-dhcp-option-parsing"},{"type":"FIX","url":"https://github.com/barebox/barebox/releases/tag/v2026.04.0"},{"type":"PACKAGE","url":"https://github.com/barebox/barebox"},{"type":"ARTICLE","url":"https://y637f9qq2x.com/posts/barebox-sandbox-vulns/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/barebox/barebox","events":[{"introduced":"0"},{"fixed":"c3e3a36f1511a7b4f34061b7be118085b80f7165"}],"database_specific":{"cpe":"cpe:2.3:a:pengutronix:barebox:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2026.04.0"}],"source":["AFFECTED_FIELD","CPE_RANGE","REFERENCES"]}}],"versions":["v2026.03.0","v2026.02.0","v2026.01.0","v2025.12.0","v2025.09.0","v2025.11.0","v2025.10.0","v2025.08.0","v2025.07.0","v2025.06.0","v2025.05.0","v2025.04.0","v2025.03.0","v2025.02.0","v2025.01.0","v2024.12.0","v2024.09.0","v2024.08.0","v2024.07.0","v2024.05.0","v2024.04.0","v2024.03.0","v2024.02.0","v2024.01.0","v2023.12.0","v2023.11.0","v2023.10.0","v2023.09.0","v2023.08.0","v2023.07.1","v2023.07.0","v2023.06.0","v2023.05.0","v2023.04.0","v2023.03.0","v2023.02.0","v2023.01.0","v2022.12.0","v2022.11.0","v2022.10.0","v2022.08.0","v2022.09.0","v2022.06.0","v2022.05.0","v2022.04.0","v2022.03.0","v2022.02.0","v2022.01.0","v2021.12.0","v2021.11.0","v2021.10.0","v2021.08.0","v2021.07.0","v2021.06.0","v2021.05.0","v2021.03.0","v2021.02.0","v2021.01.0","v2020.12.0","v2020.11.0","v2020.10.0","v2020.09.0","v2020.08.0","v2020.07.0","v2020.06.0","v2020.05.0","v2020.04.0","v2020.03.0","v2020.02.0","v2020.01.0","v2019.12.0","v2019.11.0","v2019.10.0","v2019.09.0","v2019.08.0","v2019.07.0","v2019.06.0","v2019.05.0","v2019.04.0","v2019.03.0","v2019.02.0","v2019.01.0","v2018.12.0","v2018.11.0","v2018.10.0","v2018.09.0","v2018.08.0","v2018.07.0","v2018.06.0","v2018.05.0","v2018.04.0","v2018.03.0","v2018.02.0","v2018.01.0","v2017.12.0","v2017.11.0","v2017.10.0","v2017.09.0","v2017.08.0","v2017.07.0","v2017.06.0","v2017.05.0","v2017.04.0","v2017.03.0","v2017.02.0","v2017.01.0","v2016.11.0","v2016.10.0","v2016.08.0","v2016.09.0","v2016.07.0","v2016.06.0","v2016.05.0","v2016.04.0","v2016.03.0","v2016.02.0","v2016.01.0","v2015.12.0","v2015.11.0","v2015.10.0","v2015.09.0","v2015.08.0","v2015.07.0","v2015.06.0","v2015.05.0","v2015.04.0","v2015.03.0","v2015.02.0","v2015.01.0","v2014.12.0","v2014.11.0","v2014.10.0","v2014.09.0","v2014.08.0","v2014.07.0","v2014.06.0","v2014.05.0","v2014.04.0","v2014.03.0","v2014.02.0","v2014.01.0","v2013.12.0","v2013.11.0","v2013.10.0","v2013.09.0","v2013.08.0","v2013.07.0","v2013.06.0","v2013.05.0","v2013.04.0","v2013.03.0","v2013.02.0","v2013.01.0","v2012.12.0","v2012.11.0","v2012.10.0","v2012.09.0","v2012.08.0","v2012.07.0","v2012.06.0","v2012.05.0","v2012.04.0","v2012.03.0","v2012.02.0","v2012.01.0","v2011.12.0","v2011.11.0","v2011.10.0","v2011.09.0","v2011.08.0","v2011.07.0","v2011.06.0","v2011.05.0","v2011.04.0","v2011.03.0","v2011.02.0","v2011.01.0","v2010.12.0","v2010.11.0","v2010.10.0","v2010.09.0","v2010.08.0","v2010.07.0","v2010.06.0","v2010.05.0","v2010.04.0","v2010.03.0","v2010.02.0","v2009.12.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-34960.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}