CVE-2022-29208
Description
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of tf.raw_ops.EditDistance has incomplete validation. Users can pass negative values to cause a segmentation fault based denial of service. In multiple places throughout the code, one may compute an index for a write operation. However, the existing validation only checks against the upper bound of the array. Hence, it is possible to write before the array by massaging the input to generate negative values for loc. Versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4 contain a patch for this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
tensorflowPyPI | < 2.6.4 | 2.6.4 |
tensorflowPyPI | >= 2.7.0, < 2.7.2 | 2.7.2 |
tensorflowPyPI | >= 2.8.0, < 2.8.1 | 2.8.1 |
tensorflow-cpuPyPI | < 2.6.4 | 2.6.4 |
tensorflow-cpuPyPI | >= 2.7.0, < 2.7.2 | 2.7.2 |
tensorflow-cpuPyPI | >= 2.8.0, < 2.8.1 | 2.8.1 |
tensorflow-gpuPyPI | < 2.6.4 | 2.6.4 |
tensorflow-gpuPyPI | >= 2.7.0, < 2.7.2 | 2.7.2 |
tensorflow-gpuPyPI | >= 2.8.0, < 2.8.1 | 2.8.1 |
Affected products
13cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:*range: <2.6.4
- cpe:2.3:a:google:tensorflow:2.7.0:rc0:*:*:*:*:*:*
- cpe:2.3:a:google:tensorflow:2.7.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:google:tensorflow:2.8.0:-:*:*:*:*:*:*
- cpe:2.3:a:google:tensorflow:2.8.0:rc0:*:*:*:*:*:*
- cpe:2.3:a:google:tensorflow:2.8.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:google:tensorflow:2.9.0:rc0:*:*:*:*:*:*
- cpe:2.3:a:google:tensorflow:2.9.0:rc1:*:*:*:*:*:*
- osv-coords4 versions
< 2.6.4+ 3 more
- (no CPE)range: < 2.6.4
- (no CPE)range: < 2.6.4
- (no CPE)range: < 2.6.4
- (no CPE)range: < 2.6.4
- Range: < 2.6.4
Patches
Vulnerability mechanics
References
8- github.com/tensorflow/tensorflow/commit/30721cf564cb029d34535446d6a5a6357bebc8e7nvdPatchThird Party AdvisoryWEB
- github.com/tensorflow/tensorflow/security/advisories/GHSA-2r2f-g8mw-9gvrnvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-2r2f-g8mw-9gvrghsaADVISORY
- github.com/tensorflow/tensorflow/releases/tag/v2.6.4nvdRelease NotesThird Party AdvisoryWEB
- github.com/tensorflow/tensorflow/releases/tag/v2.7.2nvdRelease NotesThird Party AdvisoryWEB
- github.com/tensorflow/tensorflow/releases/tag/v2.8.1nvdRelease NotesThird Party AdvisoryWEB
- github.com/tensorflow/tensorflow/releases/tag/v2.9.0nvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-29208ghsaADVISORY
News mentions
0No linked articles in our index yet.