VulnerabilityModified
CVE-2023-45232
EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6.
HIGH 7.5EPSS 2.10%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.10%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.10% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-835
- Affected
- tianocore/edk2
- Source
- infosec@edk2.groups.io
References
- http://packetstormsecurity.com/files/176574/PixieFail-Proof-Of-Concepts.htmlThird Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2024/01/16/2Mailing List
- https://github.com/tianocore/edk2/security/advisories/GHSA-hc6x-cw6p-gj7hVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SJ42V7O7F4OU6R7QSQQECLB6LDHKZIMQ/
- https://security.netapp.com/advisory/ntap-20240307-0011/
- http://packetstormsecurity.com/files/176574/PixieFail-Proof-Of-Concepts.htmlThird Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2024/01/16/2Mailing List
- https://github.com/tianocore/edk2/security/advisories/GHSA-hc6x-cw6p-gj7hVendor Advisory
- https://lists.debian.org/debian-lts-announce/2025/06/msg00007.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SJ42V7O7F4OU6R7QSQQECLB6LDHKZIMQ/
- https://security.netapp.com/advisory/ntap-20240307-0011/
- https://www.kb.cert.org/vuls/id/132380
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.