PT-2022-23090 · Google · Tensorflow

刘力源

·

Published

2022-09-16

·

Updated

2024-03-06

·

CVE-2022-35992

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions TensorFlow versions prior to 2.10.0 TensorFlow versions 2.9.1, 2.8.1, and 2.7.2 are also affected
Description The issue occurs when TensorListFromTensor receives an element shape of a rank greater than one, resulting in a CHECK fail that can trigger a denial of service attack. There are no known workarounds for this issue.
Recommendations For TensorFlow versions prior to 2.10.0, update to version 2.10.0 or later to resolve the issue. For TensorFlow versions 2.9.1, 2.8.1, and 2.7.2, update to the respective cherrypicked versions to resolve the issue. As a temporary workaround, consider avoiding the use of TensorListFromTensor with an element shape of a rank greater than one until a patch is available.

Exploit

Fix

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-TENSORFLOW-2022-35992
CVE-2022-35992
GHSA-9V8W-XMR4-WGXP
OPENSUSE-SU-2024:12355-1

Affected Products

Tensorflow