CVE-2023-45230: Buffer Overflow in EDK II Network Package
Buffer Overflow in EDK II Network Package
Other sources
EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.
— Ubuntu
https://blog.quarkslab.com/pixiefail-nine-vulnerabilities-in-tianocores-edk-ii-ipv6-network-stack.html https://github.com/advisories/GHSA-fc9w-pqjw-8r96
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45230?
CVE-2023-45230 has a high severity as it can lead to unauthorized access and potential loss of confidentiality, integrity, and availability.
How do I fix CVE-2023-45230?
To fix CVE-2023-45230, update EDK II to a version greater than 202311, or apply the appropriate patches if using compatible distributions such as Ubuntu or Debian.
What software is affected by CVE-2023-45230?
CVE-2023-45230 affects Tianocore EDK II and various versions across Ubuntu and Debian packages.
How can CVE-2023-45230 be exploited?
An attacker can exploit CVE-2023-45230 by sending a long server ID option in DHCPv6, leading to a buffer overflow.
Is there a workaround for CVE-2023-45230 if I cannot update immediately?
A potential workaround for CVE-2023-45230 is to disable DHCPv6 on affected systems until an update can be applied.