CVE-2023-45231: Out-of-Bounds Read in EDK II Network Package
EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.
Other sources
https://blog.quarkslab.com/pixiefail-nine-vulnerabilities-in-tianocores-edk-ii-ipv6-network-stack.html https://github.com/advisories/GHSA-pr27-mhpp-2ccr
— Red Hat
Out-of-Bounds Read in EDK II Network Package
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45231?
CVE-2023-45231 has been assigned a high severity rating due to its potential impact on system security.
How do I fix CVE-2023-45231?
To mitigate CVE-2023-45231, upgrade to one of the updated versions of EDK2 as specified in the vendor advisories.
What software is affected by CVE-2023-45231?
CVE-2023-45231 affects the Tianocore EDK2 software and specific versions of Ubuntu and Debian packages.
What are the potential exploitations of CVE-2023-45231?
CVE-2023-45231 could allow an attacker to execute arbitrary code or cause a denial of service through vulnerabilities in the IPv6 network stack.
Is CVE-2023-45231 a zero-day exploit?
CVE-2023-45231 is not a zero-day exploit as it has been publicly disclosed and mitigations are available.