CVE-2023-45232: Infinite loop in EDK II Network Package
EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.
Other sources
https://blog.quarkslab.com/pixiefail-nine-vulnerabilities-in-tianocores-edk-ii-ipv6-network-stack.html https://github.com/advisories/GHSA-3r3p-444m-2g4p
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45232?
CVE-2023-45232 has a high severity rating due to its potential to cause a denial of service attack by exploiting an infinite loop in the code.
How do I fix CVE-2023-45232?
To fix CVE-2023-45232, upgrade to the recommended versions of edk2 as specified in the affected software list.
What systems are affected by CVE-2023-45232?
CVE-2023-45232 affects various versions of the Tianocore EDK2 and corresponding packages in Ubuntu and Debian distributions.
Can CVE-2023-45232 lead to unauthorized access?
Yes, CVE-2023-45232 can potentially be exploited by attackers to gain unauthorized access due to the infinite loop vulnerability.
Is there a workaround for CVE-2023-45232 until a fix is applied?
There are no specific workarounds for CVE-2023-45232; applying the security update is essential to mitigate the vulnerability.