CVE-2022-29208

unknown
Published 2022-05-24 · Modified 2023-12-06
CVSS v3
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CVSS v2
VIR risk

Description

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.EditDistance` has incomplete validation. Users can pass negative values to cause a segmentation fault based denial of service. In multiple places throughout the code, one may compute an index for a write operation. However, the existing validation only checks against the upper bound of the array. Hence, it is possible to write before the array by massaging the input to generate negative values for `loc`. Versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4 contain a patch for this issue.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2022-29208

OS impact

OSVersionStatusFixed in
debian debianforkyfixed0
debian debiansidfixed0

Package impact

EcosystemPackageVulnerableFixed
python PyPItensorflow-cpu>=2.7.0,<2.7.22.7.2
python PyPItensorflow-cpu<2.6.42.6.4
python PyPItensorflow-gpu>=2.7.0,<2.7.22.7.2
python PyPItensorflow-gpu<2.6.42.6.4
python PyPItensorflow<2.6.42.6.4
python PyPItensorflow-cpu>=2.8.0,<2.8.12.8.1
python PyPItensorflow>=2.7.0,<2.7.22.7.2
python PyPItensorflow>=2.8.0,<2.8.12.8.1
python PyPItensorflow-gpu>=2.8.0,<2.8.12.8.1

References

Verify integrity in audit chain (admin only). AS-IS.