CVE-2022-24351

TOCTOU race-condition vulnerability in Insyde InsydeH2O with Kernel 5.2 before version 05.27.29, Kernel 5.3 before version 05.36.29, Kernel 5.4 version before 05.44.13, and Kernel 5.5 before version 05.52.13 allows an attacker to alter data and code used by the remainder of the boot process.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-12-16 02:15

Updated : 2023-12-20 17:33


NVD link : CVE-2022-24351

Mitre link : CVE-2022-24351

CVE.ORG link : CVE-2022-24351


JSON object : View

Products Affected

insyde

  • insydeh2o
CWE
CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition