5.5

CVE-2022-29209

Exploit

Type confusion leading to `CHECK`-failure based denial of service in TensorFlow

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the macros that TensorFlow uses for writing assertions (e.g., `CHECK_LT`, `CHECK_GT`, etc.) have an incorrect logic when comparing `size_t` and `int` values. Due to type conversion rules, several of the macros would trigger incorrectly. Versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4 contain a patch for this issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Google ≫ Tensorflow Version < 2.6.4
Google ≫ Tensorflow Version >= 2.7.0 < 2.7.2
Google ≫ Tensorflow Version 2.7.0 Update rc0
Google ≫ Tensorflow Version 2.7.0 Update rc1
Google ≫ Tensorflow Version 2.8.0 Update -
Google ≫ Tensorflow Version 2.8.0 Update rc0
Google ≫ Tensorflow Version 2.8.0 Update rc1
Google ≫ Tensorflow Version 2.9.0 Update rc0
Google ≫ Tensorflow Version 2.9.0 Update rc1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.307
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:N/A:P
security-advisories@github.com 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

https://github.com/tensorflow/tensorflow/releases/tag/v2.6.4
Third Party Advisory
Release Notes
https://github.com/tensorflow/tensorflow/releases/tag/v2.7.2
Third Party Advisory
Release Notes
https://github.com/tensorflow/tensorflow/releases/tag/v2.8.1
Third Party Advisory
Release Notes
https://github.com/tensorflow/tensorflow/releases/tag/v2.9.0
Third Party Advisory
Release Notes
https://github.com/tensorflow/tensorflow/blob/f3b9bf4c3c0597563b289c0512e98d4ce81f886e/tensorflow/core/platform/default/logging.h
Third Party Advisory
https://github.com/tensorflow/tensorflow/commit/b917181c29b50cb83399ba41f4d938dc369109a1
Patch
Third Party Advisory
https://github.com/tensorflow/tensorflow/issues/55530
Third Party Advisory
Exploit
Issue Tracking
https://github.com/tensorflow/tensorflow/pull/55730
Patch
Third Party Advisory
Exploit
Issue Tracking
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-f4rr-5m7v-wxcw
Patch
Third Party Advisory
Exploit