VDB

CVE-2022-29207

CVE-2022-29207 PUBLISHED CVSS 5.5 MEDIUM

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, multiple TensorFlow operations misbehave in eager mode when the resource handle provided to them is invalid. In graph mode, it would have been impossible to perform these API calls, but migration to TF 2.x eager mode opened up this vulnerability. If the resource handle is empty, then a reference is bound to a null pointer inside TensorFlow codebase (various codepaths). This is undefined behavior. Versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4 contain a patch for this issue.

EPSS 0.32% · 25.2th percentile

Risk Scores

CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.32%
25.2th percentile

Affected Products

VendorProductVersions
Bitnamitensorflow0, 2.7.0, 2.8.0
Bitnamitensorflow0, 2.7.0, 2.8.0

Timeline

  • May 20, 2022 CVE Published
  • May 21, 2022 EPSS Score
  • Jul 9, 2022 EPSS Score
  • Aug 28, 2022 EPSS Score
  • Oct 17, 2022 EPSS Score
  • Dec 5, 2022 EPSS Score
  • Jan 23, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 13, 2023 EPSS Score
  • May 2, 2023 EPSS Score
  • Jun 20, 2023 EPSS Score
  • Aug 8, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›