CVE Vulnerabilities

CVE-2022-27540

Time-of-check Time-of-use (TOCTOU) Race Condition

Published: Jun 28, 2024 | Modified: Jan 30, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.

Weakness

The product checks the state of a resource before using that resource, but the resource’s state can change between the check and the use in a way that invalidates the results of the check.

Affected Software

NameVendorStart VersionEnd Version
Dragonfly_folio_13.5_inch_g3_2-in-1_notebook_pc_firmwareHp*01.07.00 (excluding)

Potential Mitigations

References