PT-2022-16082 · Google · Tensorflow

·

CVE-2022-23566

·

Published

2022-02-04

·

Updated

2026-07-09

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TensorFlow versions prior to 2.8.0 TensorFlow versions 2.7.0 through 2.7.1 TensorFlow versions 2.6.0 through 2.6.3 TensorFlow versions 2.5.0 through 2.5.3
Description TensorFlow is vulnerable to a heap out-of-bounds (OOB) write in Grappler. The set output function writes to an array at the specified index, giving a malicious user a write primitive.
Recommendations For versions prior to 2.8.0, update to TensorFlow 2.8.0 or later. For versions 2.7.0 through 2.7.1, update to TensorFlow 2.7.1. For versions 2.6.0 through 2.6.3, update to TensorFlow 2.6.3. For versions 2.5.0 through 2.5.3, update to TensorFlow 2.5.3.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-TENSORFLOW-2022-23566
CVE-2022-23566
GHSA-5QW5-89MW-WCG2
OPENSUSE-SU-2024:12116-1
PYSEC-2022-130
PYSEC-2022-75
PYSEC-2026-3109

Affected Products

Tensorflow