CVE-2023-45233: Infinite loop in EDK II Network Package
EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.
Other sources
https://blog.quarkslab.com/pixiefail-nine-vulnerabilities-in-tianocores-edk-ii-ipv6-network-stack.html https://github.com/advisories/GHSA-p9h6-p7cr-7842
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45233?
CVE-2023-45233 has a high severity level due to the risk of an infinite loop vulnerability which can lead to a loss of availability.
How do I fix CVE-2023-45233?
To fix CVE-2023-45233, upgrade to the appropriate patched version of the EDK2 package as specified for your operating system.
What systems are affected by CVE-2023-45233?
CVE-2023-45233 affects various versions of the EDK2 package on Ubuntu and Debian systems.
What could an attacker exploit using CVE-2023-45233?
An attacker could exploit CVE-2023-45233 to create an infinite loop, leading to system unavailability and potential unauthorized access.
Is there a common workaround for CVE-2023-45233?
There are no known workarounds for CVE-2023-45233; the recommended action is to apply the provided updates.