PT-2022-16109 · Google · Tensorflow

Mihaimaruseac

·

Published

2022-02-04

·

Updated

2024-03-06

·

CVE-2022-23592

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions TensorFlow version 2.8.0
Description The type inference in TensorFlow can cause a heap out of bounds read due to inadequate bounds checking, which is done in a DCHECK that is a no-op during production. An attacker can manipulate the input idx variable to make ix larger than the number of values in node t.args, leading to the issue.
Recommendations For TensorFlow version 2.8.0, update to a version that includes the fix, which will be available in TensorFlow 2.8.0. As a temporary workaround, consider restricting access to the type inference functionality until the update is applied.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-TENSORFLOW-2022-23592
CVE-2022-23592
GHSA-VQ36-27G6-P492
PYSEC-2022-101
PYSEC-2022-156

Affected Products

Tensorflow