]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commit
ovmf: Fix CVE-2023-45237
authorSoumya Sambu <soumya.sambu@windriver.com>
Fri, 2 Aug 2024 03:34:33 +0000 (03:34 +0000)
committerHongxu Jia <hongxu.jia@windriver.com>
Wed, 4 Dec 2024 03:30:12 +0000 (11:30 +0800)
commit6f8bdaad9d22e65108f859a695277ce1b20ef7c6
treea2da80eb822fe0a6f7a356014e50b47a21606973
parent23a87c571ae4cdd285a96af0d458906aaf8c4571
ovmf: Fix CVE-2023-45237

EDK2's Network Package is susceptible to a predictable TCP Initial Sequence
Number. This vulnerability can be exploited by an attacker to gain
unauthorized access and potentially lead to a loss of Confidentiality.

References:
https://nvd.nist.gov/vuln/detail/CVE-2023-45237

Upstream-patches:
https://github.com/tianocore/edk2/commit/cf07238e5fa4f8b1138ac1c9e80530b4d4e59f1c
https://github.com/tianocore/edk2/commit/4c4ceb2ceb80c42fd5545b2a4bd80321f07f4345

Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com>
meta/recipes-core/ovmf/ovmf/CVE-2023-45237-0001.patch [new file with mode: 0644]
meta/recipes-core/ovmf/ovmf/CVE-2023-45237-0002.patch [new file with mode: 0644]
meta/recipes-core/ovmf/ovmf_git.bb