PT-2022-16085 · Google · Tensorflow

Faysal Hossain Shezan

·

Published

2022-02-03

·

Updated

2024-03-06

·

CVE-2022-23569

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions TensorFlow versions prior to 2.8.0 TensorFlow versions 2.7.1, 2.6.3, and 2.5.3 are also affected
Description Multiple operations in TensorFlow can be used to trigger a denial of service via CHECK-fails (i.e., assertion failures). This issue is similar to previous instances and has similar fixes. The reported issues have been patched in multiple GitHub commits. It is possible that other similar instances exist in TensorFlow, and fixes will be issued as these are discovered.
Recommendations For versions prior to 2.8.0, update to TensorFlow 2.8.0 to resolve the issue. For version 2.7.1, update to a newer version that includes the cherrypicked commit. For version 2.6.3, update to a newer version that includes the cherrypicked commit. For version 2.5.3, update to a newer version that includes the cherrypicked commit. As a temporary workaround, consider disabling the CHECK-fails (i.e., assertion failures) until a patch is available.

Exploit

Fix

Assertion Failure

Weakness Enumeration

Related Identifiers

BIT-TENSORFLOW-2022-23569
CVE-2022-23569
GHSA-QJ5R-F9MV-RFFH
OPENSUSE-SU-2024:12116-1
PYSEC-2022-133
PYSEC-2022-78

Affected Products

Tensorflow