Improper resource allocation - Buffer overflow In edk2
Description
EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 2020.11-2+deb11u3 | ||
debian 12 | 2022.11-6+deb12u1 | ||
debian 13 | 2023.11-6 | ||
debian 14 | 2023.11-6 | ||
rpm rhel8.8 | 0:20220126gitbb1bba3d77-4.el8_8.5 | ||
rpm rhel8 | 0:20220126gitbb1bba3d77-13.el8_10 | ||
rpm rhel9 | 0:20231122-6.el9 | ||
rpm rhel9.2 | 0:20221207gitfff6d81270b5-9.el9_2.3 |
Aliases
1. 2. 3. 4. 5.