CVE-2022-23588

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/02/2022
Last modified:
10/02/2022

Description

Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that Grappler optimizer would attempt to build a tensor using a reference `dtype`. This would result in a crash due to a `CHECK`-fail in the `Tensor` constructor as reference types are not allowed. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow 2.6.3, and TensorFlow 2.5.3, as these are also affected and still in supported range.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:* 2.5.2 (including)
cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:* 2.6.0 (including) 2.6.2 (including)
cpe:2.3:a:google:tensorflow:2.7.0:*:*:*:*:*:*:*