Logo
vulnerabilityCVE-2023-45232
Name
CVE-2023-45232
Source
NVD ( link)Debian ( link)
Description
EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
ovmf
Patched

Vulnerability Ratings#


7.5
CVSSv31
7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
edk2-stable202411
Not Affected
buildroot
master
edk2-stable202602
Not Affected
yocto
master
edk2-stable202511
Not Affected
yocto
scarthgap
edk2-stable202402
Not Affected

Resolved with patches#


ovmf (yocto:kirkstone)

#
Title
Author
Resolve
1
NetworkPkg: Ip6Dxe: SECURITY PATCH CVE-2023-45232 Unit Tests
Doug Flick <dougflick@microsoft.com>
CVE-2023-45232
CVE-2023-45233
2
NetworkPkg: Ip6Dxe: SECURITY PATCH CVE-2023-45232 Patch
Doug Flick <dougflick@microsoft.com>
CVE-2023-45232
CVE-2023-45233