5.5

CVE-2022-29199

Exploit

Missing validation causes denial of service in TensorFlow via `LoadAndRemapMatrix`

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.LoadAndRemapMatrix does not fully validate the input arguments. This results in a `CHECK`-failure which can be used to trigger a denial of service attack. The code assumes `initializing_values` is a vector but there is no validation for this before accessing its value. Versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4 contain a patch for this issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Google ≫ Tensorflow Version < 2.6.4
Google ≫ Tensorflow Version >= 2.7.0 < 2.7.2
Google ≫ Tensorflow Version 2.7.0 Update rc0
Google ≫ Tensorflow Version 2.7.0 Update rc1
Google ≫ Tensorflow Version 2.8.0 Update -
Google ≫ Tensorflow Version 2.8.0 Update rc0
Google ≫ Tensorflow Version 2.8.0 Update rc1
Google ≫ Tensorflow Version 2.9.0 Update rc0
Google ≫ Tensorflow Version 2.9.0 Update rc1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.232
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:N/A:P
security-advisories@github.com 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://github.com/tensorflow/tensorflow/releases/tag/v2.6.4
Third Party Advisory
Release Notes
https://github.com/tensorflow/tensorflow/releases/tag/v2.7.2
Third Party Advisory
Release Notes
https://github.com/tensorflow/tensorflow/releases/tag/v2.8.1
Third Party Advisory
Release Notes
https://github.com/tensorflow/tensorflow/releases/tag/v2.9.0
Third Party Advisory
Release Notes
https://github.com/tensorflow/tensorflow/blob/f3b9bf4c3c0597563b289c0512e98d4ce81f886e/tensorflow/core/kernels/load_and_remap_matrix_op.cc#L70-L98
Third Party Advisory
https://github.com/tensorflow/tensorflow/commit/3150642acbbe254e3c3c5d2232143fa591855ac9
Patch
Third Party Advisory
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-p9rc-rmr5-529j
Patch
Third Party Advisory
Exploit