{"id":"AZL-39553","summary":"CVE-2023-45232 affecting package hvloader for versions less than 1.0.1-9","details":"EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This\n vulnerability can be exploited by an attacker to gain unauthorized \naccess and potentially lead to a loss of Availability.","modified":"2026-04-01T05:13:49.459081Z","published":"2024-01-16T16:15:12Z","upstream":["CVE-2023-45232"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-45232"}],"affected":[{"package":{"name":"hvloader","ecosystem":"Azure Linux:2","purl":"pkg:rpm/azure-linux/hvloader"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.1-9"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-39553.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}