VDB
CVE-2022-29212
CVE-2022-29212
PUBLISHED
CVSS 5.5 MEDIUM
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, certain TFLite models that were created using TFLite model converter would crash when loaded in the TFLite interpreter. The culprit is that during quantization the scale of values could be greater than 1 but code was always assuming sub-unit scaling. Thus, since code was calling `QuantizeMultiplierSmallerThanOneExp`, the `TFLITE_CHECK_LT` assertion would trigger and abort the process. Versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4 contain a patch for this issue.
EPSS 0.32% · 25.1th percentile
Risk Scores
CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.32%
25.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | tensorflow | 0, 2.7.0, 2.8.0 |
| Bitnami | tensorflow | 0, 2.7.0, 2.8.0 |
Timeline
- May 20, 2022 CVE Published
- May 21, 2022 EPSS Score
- Jul 9, 2022 EPSS Score
- Aug 28, 2022 EPSS Score
- Oct 17, 2022 EPSS Score
- Dec 5, 2022 EPSS Score
- Jan 23, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 13, 2023 EPSS Score
- May 2, 2023 EPSS Score
- Jun 20, 2023 EPSS Score
- Aug 8, 2023 EPSS Score
References
- https://github.com/tensorflow/tensorflow/blob/f3b9bf4c3c0597563b289c0512e98d4ce81f886e/tensorflow/lite/kernels/internal/quantization_util.cc#L114-L123 url
- https://github.com/tensorflow/tensorflow/commit/a989426ee1346693cc015792f11d715f6944f2b8 url
- https://github.com/tensorflow/tensorflow/issues/43661 url
- https://github.com/tensorflow/tensorflow/releases/tag/v2.6.4 url
- https://github.com/tensorflow/tensorflow/releases/tag/v2.7.2 url
- https://github.com/tensorflow/tensorflow/releases/tag/v2.8.1 url
- https://github.com/tensorflow/tensorflow/releases/tag/v2.9.0 url
- https://github.com/tensorflow/tensorflow/security/advisories/GHSA-8wwm-6264-x792 url
- https://nvd.nist.gov/vuln/detail/CVE-2022-29212 url