PT-2022-16082 · Google · Tensorflow

Mihaimaruseac

·

Published

2022-02-04

·

Updated

2024-03-06

·

CVE-2022-23566

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TensorFlow versions prior to 2.8.0 TensorFlow versions 2.7.0 through 2.7.1 TensorFlow versions 2.6.0 through 2.6.3 TensorFlow versions 2.5.0 through 2.5.3
Description TensorFlow is vulnerable to a heap out-of-bounds (OOB) write in Grappler. The set output function writes to an array at the specified index, giving a malicious user a write primitive.
Recommendations For versions prior to 2.8.0, update to TensorFlow 2.8.0 or later. For versions 2.7.0 through 2.7.1, update to TensorFlow 2.7.1. For versions 2.6.0 through 2.6.3, update to TensorFlow 2.6.3. For versions 2.5.0 through 2.5.3, update to TensorFlow 2.5.3.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

BIT-TENSORFLOW-2022-23566
CVE-2022-23566
GHSA-5QW5-89MW-WCG2
OPENSUSE-SU-2024:12116-1
PYSEC-2022-130
PYSEC-2022-75

Affected Products

Tensorflow