VDB

CVE-2022-29208

CVE-2022-29208 PUBLISHED CVSS 7.099999904632568 HIGH

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.EditDistance` has incomplete validation. Users can pass negative values to cause a segmentation fault based denial of service. In multiple places throughout the code, one may compute an index for a write operation. However, the existing validation only checks against the upper bound of the array. Hence, it is possible to write before the array by massaging the input to generate negative values for `loc`. Versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4 contain a patch for this issue.

EPSS 0.38% · 32.0th percentile

Risk Scores

CVSS 3.1
7.099999904632568
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
EPSS Score
0.38%
32.0th percentile

Affected Products

VendorProductVersions
Bitnamitensorflow0, 2.8.0, 2.7.0
Bitnamitensorflow0, 2.7.0, 2.8.0

Timeline

  • May 20, 2022 CVE Published
  • May 21, 2022 EPSS Score
  • May 24, 2022 CVE Updated
  • Jul 9, 2022 EPSS Score
  • Aug 28, 2022 EPSS Score
  • Oct 17, 2022 EPSS Score
  • Dec 5, 2022 EPSS Score
  • Jan 23, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 13, 2023 EPSS Score
  • May 1, 2023 EPSS Score
  • Jun 20, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›