PT-2022-26128 · Google · Tensorflow
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
TensorFlow versions prior to 2.11
TensorFlow versions 2.10.1, 2.9.3, and 2.8.4
Description
TensorFlow is an open source platform for machine learning. If
FractionMaxPoolGrad is given outsize inputs row pooling sequence and col pooling sequence, TensorFlow will crash.Recommendations
For versions prior to 2.11, update to TensorFlow 2.11.
For version 2.10.1, apply the patch from GitHub commit d71090c3e5ca325bdf4b02eb236cfb3ee823e927 or update to a newer version.
For version 2.9.3, apply the patch from GitHub commit d71090c3e5ca325bdf4b02eb236cfb3ee823e927 or update to a newer version.
For version 2.8.4, apply the patch from GitHub commit d71090c3e5ca325bdf4b02eb236cfb3ee823e927 or update to a newer version.
As a temporary workaround, consider restricting the use of
FractionMaxPoolGrad until a patch is available.Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tensorflow