PT-2022-19466 · Google · Tensorflow

Mihaimaruseac

·

Published

2022-05-20

·

Updated

2024-03-06

·

CVE-2022-29213

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions TensorFlow versions prior to 2.9.0 TensorFlow versions prior to 2.8.1 TensorFlow versions prior to 2.7.2 TensorFlow versions prior to 2.6.4
Description The issue is related to the lack of input validation in the tf.compat.v1.signal.rfft2d and tf.compat.v1.signal.rfft3d functions, which can result in crashes due to CHECK-failures under certain conditions.
Recommendations For versions prior to 2.9.0, update to version 2.9.0 or later. For versions prior to 2.8.1, update to version 2.8.1 or later. For versions prior to 2.7.2, update to version 2.7.2 or later. For versions prior to 2.6.4, update to version 2.6.4 or later.

Exploit

Fix

Assertion Failure

RCE

Weakness Enumeration

Related Identifiers

BIT-TENSORFLOW-2022-29213
CVE-2022-29213
GHSA-5889-7V45-Q28M

Affected Products

Tensorflow