PT-2022-23093 · Google · Tensorflow

刘力源

·

Published

2022-09-16

·

Updated

2024-03-06

·

CVE-2022-35995

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions TensorFlow versions prior to 2.10.0 TensorFlow versions 2.9.1, 2.8.1, and 2.7.2 are also affected
Description The issue occurs when AudioSummaryV2 receives an input sample rate with more than one element, resulting in a CHECK failure that can be used to trigger a denial of service attack. There are no known workarounds for this issue.
Recommendations For TensorFlow versions prior to 2.10.0, update to version 2.10.0 or later to resolve the issue. For TensorFlow versions 2.9.1, 2.8.1, and 2.7.2, update to the respective patched versions to resolve the issue. As a temporary workaround, consider avoiding the use of AudioSummaryV2 with input sample rate having more than one element until a patch is available.

Exploit

Fix

Assertion Failure

Weakness Enumeration

Related Identifiers

BIT-TENSORFLOW-2022-35995
CVE-2022-35995
GHSA-G9H5-VR8M-X2H4
OPENSUSE-SU-2024:12355-1

Affected Products

Tensorflow