PT-2022-15070 · Google · Tensorflow

Yu Tian

·

Published

2022-02-03

·

Updated

2024-03-06

·

CVE-2022-21730

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions TensorFlow versions prior to 2.8.0 TensorFlow versions 2.7.1 and earlier TensorFlow versions 2.6.3 and earlier TensorFlow versions 2.5.3 and earlier
Description The implementation of FractionalAvgPoolGrad does not consider cases where the input tensors are invalid, allowing an attacker to read from outside of bounds of heap. This issue can be exploited by providing invalid input tensors to the FractionalAvgPoolGrad function.
Recommendations For versions prior to 2.8.0, update to TensorFlow 2.8.0 or later. For versions 2.7.1 and earlier, update to TensorFlow 2.7.1 or later. For versions 2.6.3 and earlier, update to TensorFlow 2.6.3 or later. For versions 2.5.3 and earlier, update to TensorFlow 2.5.3 or later. As a temporary workaround, consider restricting the use of the FractionalAvgPoolGrad function until a patch is available.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

BIT-TENSORFLOW-2022-21730
CVE-2022-21730
GHSA-VJG4-V33C-GGC4
OPENSUSE-SU-2024:12116-1
PYSEC-2022-109
PYSEC-2022-54

Affected Products

Tensorflow