{"id":"AZL-39346","summary":"CVE-2023-45232 affecting package edk2 for versions less than 20230301gitf80f052277c8-40","details":"EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This\n vulnerability can be exploited by an attacker to gain unauthorized \naccess and potentially lead to a loss of Availability.","modified":"2026-04-01T05:13:25.574220Z","published":"2024-01-16T16:15:12Z","upstream":["CVE-2023-45232"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-45232"}],"affected":[{"package":{"name":"edk2","ecosystem":"Azure Linux:2","purl":"pkg:rpm/azure-linux/edk2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20230301gitf80f052277c8-40"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-39346.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}