EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This
vulnerability can be exploited by an attacker to gain unauthorized
access and potentially lead to a loss of Availability.
References
Configurations
History
13 Mar 2024, 02:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
07 Mar 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
23 Jan 2024, 19:39
Type | Values Removed | Values Added |
---|---|---|
First Time |
Tianocore
Tianocore edk2 |
|
CWE | CWE-835 | |
References | () http://www.openwall.com/lists/oss-security/2024/01/16/2 - Mailing List | |
References | () http://packetstormsecurity.com/files/176574/PixieFail-Proof-Of-Concepts.html - Third Party Advisory, VDB Entry | |
References | () https://github.com/tianocore/edk2/security/advisories/GHSA-hc6x-cw6p-gj7h - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
CPE | cpe:2.3:a:tianocore:edk2:*:*:*:*:*:*:*:* |
17 Jan 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
16 Jan 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
16 Jan 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-01-16 16:15
Updated : 2024-03-13 02:15
NVD link : CVE-2023-45232
Mitre link : CVE-2023-45232
CVE.ORG link : CVE-2023-45232
JSON object : View
Products Affected
tianocore
- edk2
CWE
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')