FlawAtlas
Search the atlas
SUSE-SU-2026:0196-1 Not scored

Security update for ovmf

This update for ovmf fixes the following issues: - CVE-2023-45231: Fixed out of bounds read when handling a ND Redirect message with truncated options (bsc#1218881). - CVE-2023-45232: Fixed infinite loop when parsing unknown options in the Destination Options header (bsc#1218882). - CVE-2023-45233: Fixed infinite loop when parsing a PadN option in the Destination Options header (bsc#1218883). - CVE-2023-45234: Fixed buffer overflow when processing DNS Servers option in a DHCPv6 Advertise message (bsc#1218884). - CVE-2023-45235: Fixed buffer overflow when handling Server ID option from a DHCPv6 proxy Advertise message (bsc#1218885).

Exploit probability Not scored
Published January 21, 2026
Required by Not available
Last source change March 23, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Server 12 SP5-LTSS ovmf
SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5 ovmf

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:0196-1

This update for ovmf fixes the following issues: - CVE-2023-45231: Fixed out of bounds read when handling a ND Redirect message with truncated options (bsc#1218881). - CVE-2023-45232: Fixed infinite loop when parsing unknown options in the Destination Options header (bsc#1218882). - CVE-2023-45233: Fixed infinite loop when parsing a PadN option in the Destination Options header (bsc#1218883). - CVE-2023-45234: Fixed buffer overflow when processing DNS Servers option in a DHCPv6 Advertise message (bsc#1218884). - CVE-2023-45235: Fixed buffer overflow when handling Server ID option from a DHCPv6 proxy Advertise message (bsc#1218885).

View original source

05 / REFERENCES

Further evidence