Skip to content

Commit

Permalink
ovmf: Fix CVE-2023-45229
Browse files Browse the repository at this point in the history
EDK2's Network Package is susceptible to an out-of-bounds read
vulnerability when processing the IA_NA or IA_TA option in a DHCPv6
Advertise message. This vulnerability can be exploited by an attacker
to gain unauthorized access and potentially lead to a loss of
Confidentiality.

References:
https://nvd.nist.gov/vuln/detail/CVE-2023-45229

Upstream-patches:
tianocore/edk2@1dbb10c
tianocore/edk2@0736276
tianocore/edk2@1c440a5
tianocore/edk2@1d0b95f

Signed-off-by: Soumya Sambu <[email protected]>
  • Loading branch information
SoumyaWind authored and hongxu-jia committed Dec 4, 2024
1 parent dd26902 commit 23a87c5
Show file tree
Hide file tree
Showing 5 changed files with 1,548 additions and 0 deletions.
Loading

0 comments on commit 23a87c5

Please sign in to comment.