cbcvebase.
CVE-2023-45232
published 2024-01-16

CVE-2023-45232: EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianedk2< edk2 2022.11-6+deb12u1 (bookworm)edk2 2022.11-6+deb12u1 (bookworm)
msrcazl3_edk2_20230301gitf80f052277c8-37_on_azure_linux_3.0
msrcazl3_edk2_20240223gitedc6681206c1-1_on_azure_linux_3.0
msrcazl3_qemu_8.2.0-16_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_edk2_20230301gitf80f052277c8-40_on_cbl_mariner_2.0
msrccbl2_edk2_20230301gitf80f052277c8-41_on_cbl_mariner_2.0
msrccbl2_hvloader_1.0.1-11_on_cbl_mariner_2.0
msrccbl2_hvloader_1.0.1-9_on_cbl_mariner_2.0
msrccbl2_qemu_6.2.0-24_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
paloaltopan-os
paloaltoprisma_access
tianocoreedk2<= 202311
tianocoreedk2
tianocoreedk2>= 0 < 2020.11-2+deb11u32020.11-2+deb11u3
tianocoreedk2>= 0 < 2022.11-6+deb12u12022.11-6+deb12u1
tianocoreedk2>= 0 < 2023.11-62023.11-6
tianocoreedk2>= 0 < 2023.11-62023.11-6
tianocoreedk2>= 0 < 0~20191122.bd85bf54-2ubuntu3.50~20191122.bd85bf54-2ubuntu3.5
tianocoreedk2>= 0 < 2022.02-3ubuntu0.22.04.22022.02-3ubuntu0.22.04.2

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH