CVE-2022-36027

TensorFlow is an open source platform for machine learning. When converting transposed convolutions using per-channel weight quantization the converter segfaults and crashes the Python process. We have patched the issue in GitHub commit aa0b852a4588cea4d36b74feb05d93055540b450. The fix will be included in TensorFlow 2.10.0. We will also cherrypick this commit on TensorFlow 2.9.1, TensorFlow 2.8.1, and TensorFlow 2.7.2, as these are also affected and still in supported range. There are no known workarounds for this issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:*
cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:*
cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:*
cpe:2.3:a:google:tensorflow:2.10:rc0:*:*:*:*:*:*
cpe:2.3:a:google:tensorflow:2.10:rc1:*:*:*:*:*:*
cpe:2.3:a:google:tensorflow:2.10:rc2:*:*:*:*:*:*
cpe:2.3:a:google:tensorflow:2.10:rc3:*:*:*:*:*:*

History

20 Sep 2022, 14:38

Type Values Removed Values Added
First Time Google tensorflow
Google
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:google:tensorflow:2.10:rc1:*:*:*:*:*:*
cpe:2.3:a:google:tensorflow:2.10:rc2:*:*:*:*:*:*
cpe:2.3:a:google:tensorflow:2.10:rc3:*:*:*:*:*:*
cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:*
cpe:2.3:a:google:tensorflow:2.10:rc0:*:*:*:*:*:*
CWE CWE-20 NVD-CWE-noinfo
References (MISC) https://github.com/tensorflow/tensorflow/commit/aa0b852a4588cea4d36b74feb05d93055540b450 - (MISC) https://github.com/tensorflow/tensorflow/commit/aa0b852a4588cea4d36b74feb05d93055540b450 - Patch, Third Party Advisory
References (MISC) https://github.com/tensorflow/tensorflow/issues/53767 - (MISC) https://github.com/tensorflow/tensorflow/issues/53767 - Exploit, Third Party Advisory
References (CONFIRM) https://github.com/tensorflow/tensorflow/security/advisories/GHSA-79h2-q768-fpxr - (CONFIRM) https://github.com/tensorflow/tensorflow/security/advisories/GHSA-79h2-q768-fpxr - Third Party Advisory

16 Sep 2022, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-09-16 23:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-36027

Mitre link : CVE-2022-36027

CVE.ORG link : CVE-2022-36027


JSON object : View

Products Affected

google

  • tensorflow
CWE
NVD-CWE-noinfo CWE-20

Improper Input Validation