{"id":"AZL-38227","summary":"CVE-2023-45232 affecting package edk2 for versions less than 20240223gitedc6681206c1-1","details":"EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This\n vulnerability can be exploited by an attacker to gain unauthorized \naccess and potentially lead to a loss of Availability.","modified":"2026-04-01T05:13:17.959508Z","published":"2024-01-16T16:15:12Z","upstream":["CVE-2023-45232"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-45232"}],"affected":[{"package":{"name":"edk2","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/edk2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20240223gitedc6681206c1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-38227.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}