Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

SUSE: 2025:0421-1 important: ovmf buffer overflow and out-of-bounds issues

suse
Calendar Grey February 11, 2025
Dist Suse Esm H88
Critical patch for ovmf resolves various vulnerabilities such as memory corruption and excessive data exposure. Ensure your system is current!
* bsc#1218879 * bsc#1218880 * bsc#1218881 * bsc#1218882 * bsc#1218883

Summary

## This update for ovmf fixes the following issues: * CVE-2023-45229: out-of-bounds read in edk2 when processing IA_NA/IA_TA options in DHCPv6 Advertise messages. (bsc#1218879) * CVE-2023-45230: buffer overflow in the DHCPv6 client in edk2 via a long Server ID option. (bsc#1218880) * CVE-2023-45231: out-of-bounds read in edk2 when handling a ND Redirect message with truncated options. (bsc#1218881) * CVE-2023-45232: infinite loop in edk2 when parsing unknown options in the Destination Options header. (bsc#1218882) * CVE-2023-45233: infinite loop in edk2 when parsing PadN options in the Destination Options header. (bsc#1218883) * CVE-2023-45234: buffer overflow in edk2 when processing DNS Servers options in a DHCPv6 Advertise message. (bsc#1218884)

References

* bsc#1218879

* bsc#1218880

* bsc#1218881

* bsc#1218882

* bsc#1218883

* bsc#1218884

* bsc#1218885

* bsc#1218886

* bsc#1218887

Cross-

* CVE-2023-45229

* CVE-2023-45230

* CVE-2023-45231

* CVE-2023-45232

* CVE-2023-45233

* CVE-2023-45234

* CVE-2023-45235

* CVE-2023-45236

* CVE-2023-45237

CVSS scores:

* CVE-2023-45229 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

* CVE-2023-45229 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

* CVE-2023-45230 ( SUSE ): 8.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H

* CVE-2023-45230 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

* CVE-2023-45230 ( NVD ): 8.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H

* CVE-2023-45231 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2025:0421-1
Release Date: 2025-02-11T10:28:30Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here