VDB
DEBIAN-CVE-2023-45232
DEBIAN-CVE-2023-45232
PUBLISHED
CVSS 7.5 HIGH
EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.
Risk Scores
CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:12 | edk2 | 0, 0, 2022.11-6 |
| Debian:14 | edk2 | 0, 0, 0 |
| Debian:11 | edk2 | 2020.11-2+deb11u1, 2020.11-2+deb11u2, * |
| Debian:13 | edk2 | 0, 0, 0 |
Timeline
- Jan 16, 2024 CVE Published
- Apr 28, 2026 CVE Updated