Bug 1218882 (CVE-2023-45232) - VUL-0: CVE-2023-45232: edk2, ovmf: Infinite loop when parsing unknown options in the Destination Options header
Summary: VUL-0: CVE-2023-45232: edk2, ovmf: Infinite loop when parsing unknown options...
Status: NEW
Alias: CVE-2023-45232
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Assignee: Joey Lee
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/391380/
Whiteboard: CVSSv3.1:SUSE:CVE-2023-45232:7.5:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2024-01-17 04:37 UTC by SMASH SMASH
Modified: 2024-05-17 11:24 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---
stoyan.manolov: needinfo? (jlee)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2024-01-17 04:37:19 UTC
EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This
 vulnerability can be exploited by an attacker to gain unauthorized 
access and potentially lead to a loss of Availability.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-45232
https://www.cve.org/CVERecord?id=CVE-2023-45232
https://github.com/tianocore/edk2/security/advisories/GHSA-hc6x-cw6p-gj7h
http://www.openwall.com/lists/oss-security/2024/01/16/2
https://bugzilla.redhat.com/show_bug.cgi?id=2258691