Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:0407-1

Опубликовано: 10 фев. 2025
Источник: suse-cvrf

Описание

Security update for ovmf

This update for ovmf fixes the following issues:

  • CVE-2023-45229: out-of-bounds read in edk2 when processing IA_NA/IA_TA options in DHCPv6 Advertise messages. (bsc#1218879)
  • CVE-2023-45230: buffer overflow in the DHCPv6 client in edk2 via a long Server ID option. (bsc#1218880)
  • CVE-2023-45231: out-of-bounds read in edk2 when handling a ND Redirect message with truncated options. (bsc#1218881)
  • CVE-2023-45232: infinite loop in edk2 when parsing unknown options in the Destination Options header. (bsc#1218882)
  • CVE-2023-45233: infinite loop in edk2 when parsing PadN options in the Destination Options header. (bsc#1218883)
  • CVE-2023-45234: buffer overflow in edk2 when processing DNS Servers options in a DHCPv6 Advertise message. (bsc#1218884)
  • CVE-2023-45235: buffer overflow in edk2 when handling the Server ID option in a DHCPv6 proxy Advertise message. (bsc#1218885)
  • CVE-2023-45236: predictable TCP Initial Sequence Numbers in edk2 network packages. (bsc#1218886)
  • CVE-2023-45237: use of a weak pseudorandom number generator in edk2. (bsc#1218887)

Список пакетов

SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
ovmf-202208-150500.6.6.1
ovmf-tools-202208-150500.6.6.1
qemu-ovmf-x86_64-202208-150500.6.6.1
qemu-uefi-aarch64-202208-150500.6.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
ovmf-202208-150500.6.6.1
ovmf-tools-202208-150500.6.6.1
qemu-ovmf-x86_64-202208-150500.6.6.1
qemu-uefi-aarch64-202208-150500.6.6.1
SUSE Linux Enterprise Micro 5.5
qemu-ovmf-x86_64-202208-150500.6.6.1
qemu-uefi-aarch64-202208-150500.6.6.1
SUSE Linux Enterprise Server 15 SP5-LTSS
ovmf-202208-150500.6.6.1
ovmf-tools-202208-150500.6.6.1
qemu-ovmf-x86_64-202208-150500.6.6.1
qemu-uefi-aarch64-202208-150500.6.6.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
ovmf-202208-150500.6.6.1
ovmf-tools-202208-150500.6.6.1
qemu-ovmf-x86_64-202208-150500.6.6.1

Описание

EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:ovmf-202208-150500.6.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:ovmf-tools-202208-150500.6.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:qemu-ovmf-x86_64-202208-150500.6.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:qemu-uefi-aarch64-202208-150500.6.6.1

Ссылки

Описание

EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:ovmf-202208-150500.6.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:ovmf-tools-202208-150500.6.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:qemu-ovmf-x86_64-202208-150500.6.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:qemu-uefi-aarch64-202208-150500.6.6.1

Ссылки

Описание

EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:ovmf-202208-150500.6.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:ovmf-tools-202208-150500.6.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:qemu-ovmf-x86_64-202208-150500.6.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:qemu-uefi-aarch64-202208-150500.6.6.1

Ссылки

Описание

EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:ovmf-202208-150500.6.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:ovmf-tools-202208-150500.6.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:qemu-ovmf-x86_64-202208-150500.6.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:qemu-uefi-aarch64-202208-150500.6.6.1

Ссылки

Описание

EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:ovmf-202208-150500.6.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:ovmf-tools-202208-150500.6.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:qemu-ovmf-x86_64-202208-150500.6.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:qemu-uefi-aarch64-202208-150500.6.6.1

Ссылки

Описание

EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:ovmf-202208-150500.6.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:ovmf-tools-202208-150500.6.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:qemu-ovmf-x86_64-202208-150500.6.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:qemu-uefi-aarch64-202208-150500.6.6.1

Ссылки

Описание

EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:ovmf-202208-150500.6.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:ovmf-tools-202208-150500.6.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:qemu-ovmf-x86_64-202208-150500.6.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:qemu-uefi-aarch64-202208-150500.6.6.1

Ссылки

Описание

EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:ovmf-202208-150500.6.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:ovmf-tools-202208-150500.6.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:qemu-ovmf-x86_64-202208-150500.6.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:qemu-uefi-aarch64-202208-150500.6.6.1

Ссылки

Описание

EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:ovmf-202208-150500.6.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:ovmf-tools-202208-150500.6.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:qemu-ovmf-x86_64-202208-150500.6.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:qemu-uefi-aarch64-202208-150500.6.6.1

Ссылки
Уязвимость SUSE-SU-2025:0407-1