Bug ID 1218882
Summary VUL-0: CVE-2023-45232: edk2, ovmf: Infinite loop when parsing unknown options in the Destination Options header
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.6
Hardware Other
URL https://smash.suse.de/issue/391380/
OS Other
Status NEW
Severity Major
Priority P5 - None
Component Security
Assignee guillaume.gardet@opensuse.org
Reporter smash_bz@suse.de
QA Contact security-team@suse.de
CC stoyan.manolov@suse.com
Target Milestone ---
Found By Security Response Team
Blocker ---

EDK2's Network Package is susceptible to an infinite loop vulnerability when
parsing unknown options in the Destination Options header of IPv6. This
 vulnerability can be exploited by an attacker to gain unauthorized 
access and potentially lead to a loss of Availability.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-45232
https://www.cve.org/CVERecord?id=CVE-2023-45232
https://github.com/tianocore/edk2/security/advisories/GHSA-hc6x-cw6p-gj7h
http://www.openwall.com/lists/oss-security/2024/01/16/2
https://bugzilla.redhat.com/show_bug.cgi?id=2258691


You are receiving this mail because: