PT-2022-26128 · Google · Tensorflow

·

CVE-2022-41897

·

Published

2022-11-18

·

Updated

2026-07-13

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions TensorFlow versions prior to 2.11 TensorFlow versions 2.10.1, 2.9.3, and 2.8.4
Description TensorFlow is an open source platform for machine learning. If FractionMaxPoolGrad is given outsize inputs row pooling sequence and col pooling sequence, TensorFlow will crash.
Recommendations For versions prior to 2.11, update to TensorFlow 2.11. For version 2.10.1, apply the patch from GitHub commit d71090c3e5ca325bdf4b02eb236cfb3ee823e927 or update to a newer version. For version 2.9.3, apply the patch from GitHub commit d71090c3e5ca325bdf4b02eb236cfb3ee823e927 or update to a newer version. For version 2.8.4, apply the patch from GitHub commit d71090c3e5ca325bdf4b02eb236cfb3ee823e927 or update to a newer version. As a temporary workaround, consider restricting the use of FractionMaxPoolGrad until a patch is available.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-11535
BIT-TENSORFLOW-2022-41897
CVE-2022-41897
GHSA-F2W8-JW48-FR7J
PYSEC-2026-3165
PYSEC-2026-3313
PYSEC-2026-984

Affected Products

Tensorflow