VDB
CVE-2022-23574
CVE-2022-23574
PUBLISHED
CVSS 8.800000190734863 HIGH
Tensorflow is an Open Source Machine Learning Framework. There is a typo in TensorFlow's `SpecializeType` which results in heap OOB read/write. Due to a typo, `arg` is initialized to the `i`th mutable argument in a loop where the loop index is `j`. Hence it is possible to assign to `arg` from outside the vector of arguments. Since this is a mutable proto value, it allows both read and write to outside of bounds data. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, and TensorFlow 2.6.3, as these are also affected and still in supported range.
EPSS 0.84% · 54.8th percentile
Risk Scores
CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.84%
54.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | tensorflow | 0, 2.6.0, 2.7.0 |
| Bitnami | tensorflow | 0, 2.7.0, 2.6.0 |
Timeline
- Feb 4, 2022 CVE Published
- Feb 8, 2022 EPSS Score
- Apr 2, 2022 EPSS Score
- May 24, 2022 EPSS Score
- Jul 17, 2022 EPSS Score
- Oct 30, 2022 EPSS Score
- Dec 22, 2022 EPSS Score
- Feb 12, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 6, 2023 EPSS Score
- May 28, 2023 EPSS Score
- Jul 20, 2023 EPSS Score
References
- https://github.com/tensorflow/tensorflow/blob/a1320ec1eac186da1d03f033109191f715b2b130/tensorflow/core/framework/full_type_util.cc#L81-L102 url
- https://github.com/tensorflow/tensorflow/commit/0657c83d08845cc434175934c642299de2c0f042 url
- https://github.com/tensorflow/tensorflow/security/advisories/GHSA-77gp-3h4r-6428 url
- https://nvd.nist.gov/vuln/detail/CVE-2022-23574 url