First published: Mon Apr 22 2024(Updated: )
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The CapsuleIFWUSmm driver does not check the return value from a method or function. This can prevent it from detecting unexpected states and conditions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Insyde InsydeH2O UEFI BIOS | >=5.0<=5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-46897 is classified as a medium severity vulnerability.
CVE-2022-46897 affects Insyde InsydeH2O by preventing the CapsuleIFWUSmm driver from detecting unexpected states due to lack of return value checks.
CVE-2022-46897 affects Insyde InsydeH2O running kernel versions 5.0 to 5.5.
To fix CVE-2022-46897, ensure you update Insyde InsydeH2O to a version above 5.5.
Currently, there are no official workarounds available for CVE-2022-46897; updating is the recommended action.