CVE-2022-29207

unknown
Published 2022-05-24 · Modified 2023-12-06
CVSS v3
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS v2
VIR risk

Description

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, multiple TensorFlow operations misbehave in eager mode when the resource handle provided to them is invalid. In graph mode, it would have been impossible to perform these API calls, but migration to TF 2.x eager mode opened up this vulnerability. If the resource handle is empty, then a reference is bound to a null pointer inside TensorFlow codebase (various codepaths). This is undefined behavior. Versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4 contain a patch for this issue.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2022-29207

OS impact

OSVersionStatusFixed in
debian debianforkyfixed0
debian debiansidfixed0

Package impact

EcosystemPackageVulnerableFixed
python PyPItensorflow-cpu<2.6.42.6.4
python PyPItensorflow-cpu>=2.7.0,<2.7.22.7.2
python PyPItensorflow-cpu>=2.8.0,<2.8.12.8.1
python PyPItensorflow-gpu<2.6.42.6.4
python PyPItensorflow<2.6.42.6.4
python PyPItensorflow>=2.7.0,<2.7.22.7.2
python PyPItensorflow>=2.8.0,<2.8.12.8.1
python PyPItensorflow-gpu>=2.7.0,<2.7.22.7.2
python PyPItensorflow-gpu>=2.8.0,<2.8.12.8.1

References

Verify integrity in audit chain (admin only). AS-IS.