CVE-2023-45229: Out-of-Bounds Read in EDK II Network Package
EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IANA or IATA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.
Other sources
https://blog.quarkslab.com/pixiefail-nine-vulnerabilities-in-tianocores-edk-ii-ipv6-network-stack.html https://github.com/tianocore/edk2/security/advisories/GHSA-hc6x-cw6p-gj7h
— Red Hat
Out-of-Bounds Read in EDK II Network Package
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45229?
CVE-2023-45229 is considered a high severity vulnerability affecting the Tianocore EDK II IPv6 network stack.
What software is affected by CVE-2023-45229?
CVE-2023-45229 affects Tianocore EDK II versions up to and including 202311.
How can I mitigate CVE-2023-45229?
To mitigate CVE-2023-45229, update to the latest patched version of Tianocore EDK II that addresses this vulnerability.
What are the potential impacts of CVE-2023-45229?
CVE-2023-45229 could allow unauthorized access and potential exploitation of the IPv6 network stack.
Where can I find more details about CVE-2023-45229?
More details regarding CVE-2023-45229 can be found in security advisories released by Tianocore.