CVE-2022-46897: Medium severity insyde h2o vulnerability
Published Apr 22, 2024
·Updated
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The CapsuleIFWUSmm driver does not check the return value from a method or function. This can prevent it from detecting unexpected states and conditions.
Affected Software
2 affected components
Insyde InsydeH2O>=5.0<=5.5
Insyde kernel>=5.0<=5.5
Event History
Apr 22, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-46897?
CVE-2022-46897 is classified as a medium severity vulnerability.
2
How does CVE-2022-46897 affect Insyde InsydeH2O?
CVE-2022-46897 affects Insyde InsydeH2O by preventing the CapsuleIFWUSmm driver from detecting unexpected states due to lack of return value checks.
3
What are the affected versions of Insyde InsydeH2O for CVE-2022-46897?
CVE-2022-46897 affects Insyde InsydeH2O running kernel versions 5.0 to 5.5.
4
How can I fix CVE-2022-46897?
To fix CVE-2022-46897, ensure you update Insyde InsydeH2O to a version above 5.5.
5
Is there a workaround for CVE-2022-46897?
Currently, there are no official workarounds available for CVE-2022-46897; updating is the recommended action.