Skip to content

Commit

Permalink
ovmf: Fix CVE-2023-45236
Browse files Browse the repository at this point in the history
EDK2's Network Package is susceptible to a predictable TCP Initial
Sequence Number. This vulnerability can be exploited by an attacker
to gain unauthorized access and potentially lead to a loss of
Confidentiality.

References:
https://nvd.nist.gov/vuln/detail/CVE-2023-45236

Upstream-patch:
tianocore/edk2@1904a64

Signed-off-by: Soumya Sambu <[email protected]>
  • Loading branch information
SoumyaWind authored and hongxu-jia committed Dec 4, 2024
1 parent 6f8bdaa commit a9cd332
Show file tree
Hide file tree
Showing 2 changed files with 830 additions and 0 deletions.
Loading

0 comments on commit a9cd332

Please sign in to comment.