CVE-2022-23562

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
04/02/2022
Last modified:
09/02/2022

Description

Tensorflow is an Open Source Machine Learning Framework. The implementation of `Range` suffers from integer overflows. These can trigger undefined behavior or, in some scenarios, extremely large allocations. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow 2.6.3, and TensorFlow 2.5.3, as these are also affected and still in supported range.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:* 2.5.2 (including)
cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:* 2.6.0 (including) 2.6.2 (including)
cpe:2.3:a:google:tensorflow:2.7.0:*:*:*:*:*:*:*