Infinite loop in EDK II Network Package
Published Jan 16, 2024
7.5
HIGHCVSS 3.1
EPSS 2.10%
Description
EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.
Affected products
-
- Version edk2-stable202308StatusaffectedConstraints-
- Version
No data.
Red Hat Enterprise Linux 8
edk2-0:20220126gitbb1bba3d77-13.el8_10
Fixed · RHSA-2024:3017
Red Hat Enterprise Linux 8.8 Extended Update Support
edk2-0:20220126gitbb1bba3d77-4.el8_8.6
Fixed · RHSA-2024:8104
Red Hat Enterprise Linux 9
edk2-0:20231122-6.el9
Fixed · RHSA-2024:2264
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | edk2-0:20220126gitbb1bba3d77-13.el8_10 | Fixed | RHSA-2024:3017 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | edk2-0:20220126gitbb1bba3d77-4.el8_8.6 | Fixed | RHSA-2024:8104 |
| Red Hat Enterprise Linux 9 | edk2-0:20231122-6.el9 | Fixed | RHSA-2024:2264 |
No package ranges for this CVE.
Remediation
Red Hat statement
The identified flaw in the NetworkPkg IP stack within the EDK2, an open-source UEFI implementation, poses a moderate security concern as the vulnerability allows an unauthenticated attacker within the same local network to exploit via a specifically crafted Destination Options IPv6 header.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (13)
- http://packetstormsecurity.com/files/176574/PixieFail-Proof-Of-Concepts.html Third Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2024/01/16/2 Mailing List
- https://access.redhat.com/security/cve/CVE-2023-45232 Vendor Advisory
- https://blog.quarkslab.com/pixiefail-nine-vulnerabilities-in-tianocores-edk-ii-ipv6-network-stack.html
- https://bugzilla.redhat.com/show_bug.cgi?id=2258691 Issue Tracking
- https://github.com/advisories/GHSA-3r3p-444m-2g4p
- https://github.com/tianocore/edk2/security/advisories/GHSA-hc6x-cw6p-gj7h vendor-advisoryVendor Advisory
- https://lists.debian.org/debian-lts-announce/2025/06/msg00007.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SJ42V7O7F4OU6R7QSQQECLB6LDHKZIMQ/
- https://nvd.nist.gov/vuln/detail/CVE-2023-45232
- https://security.netapp.com/advisory/ntap-20240307-0011/
- https://www.cve.org/CVERecord?id=CVE-2023-45232
- https://www.kb.cert.org/vuls/id/132380
Change history (0)
No recorded changes yet.