EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This
vulnerability can be exploited by an attacker to gain unauthorized
access and potentially lead to a loss of Availability.
References
Configurations
History
No history.
Information
Published : 2024-01-16 16:15
Updated : 2024-03-13 02:15
NVD link : CVE-2023-45232
Mitre link : CVE-2023-45232
CVE.ORG link : CVE-2023-45232
JSON object : View
Products Affected
tianocore
- edk2
CWE
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')