VDB
CVE-2022-23562
CVE-2022-23562
PUBLISHED
CVSS 8.800000190734863 HIGH
Tensorflow is an Open Source Machine Learning Framework. The implementation of `Range` suffers from integer overflows. These can trigger undefined behavior or, in some scenarios, extremely large allocations. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow 2.6.3, and TensorFlow 2.5.3, as these are also affected and still in supported range.
EPSS 0.58% · 45.8th percentile
Risk Scores
CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.58%
45.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | tensorflow | 0, 2.6.0, 2.7.0 |
| Bitnami | tensorflow | 0, 2.6.0, 2.7.0 |
Timeline
- Feb 4, 2022 CVE Published
- Feb 8, 2022 EPSS Score
- Apr 2, 2022 EPSS Score
- May 25, 2022 EPSS Score
- Jul 18, 2022 EPSS Score
- Sep 9, 2022 EPSS Score
- Nov 1, 2022 EPSS Score
- Dec 24, 2022 EPSS Score
- Feb 15, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 9, 2023 EPSS Score
- Jun 1, 2023 EPSS Score
References
- https://github.com/tensorflow/tensorflow/commit/f0147751fd5d2ff23251149ebad9af9f03010732 url
- https://github.com/tensorflow/tensorflow/issues/52676 url
- https://github.com/tensorflow/tensorflow/pull/51733 url
- https://github.com/tensorflow/tensorflow/security/advisories/GHSA-qx3f-p745-w4hr url
- https://nvd.nist.gov/vuln/detail/CVE-2022-23562 url