CVE-2022-41884

TensorFlow is an open source platform for machine learning. If a numpy array is created with a shape such that one element is zero and the others sum to a large number, an error will be raised. We have patched the issue in GitHub commit 2b56169c16e375c521a3bc8ea658811cc0793784. The fix will be included in TensorFlow 2.11. We will also cherrypick this commit on TensorFlow 2.10.1, 2.9.3, and TensorFlow 2.8.4, as these are also affected and still in supported range.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:*
cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:*
cpe:2.3:a:google:tensorflow:2.10.0:*:*:*:*:*:*:*

History

22 Nov 2022, 21:53

Type Values Removed Values Added
References (CONFIRM) https://github.com/tensorflow/tensorflow/security/advisories/GHSA-jq6x-99hj-q636 - (CONFIRM) https://github.com/tensorflow/tensorflow/security/advisories/GHSA-jq6x-99hj-q636 - Exploit, Patch, Third Party Advisory
References (MISC) https://github.com/tensorflow/tensorflow/commit/2b56169c16e375c521a3bc8ea658811cc0793784 - (MISC) https://github.com/tensorflow/tensorflow/commit/2b56169c16e375c521a3bc8ea658811cc0793784 - Patch, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Google tensorflow
Google
CPE cpe:2.3:a:google:tensorflow:2.10.0:*:*:*:*:*:*:*
cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:*

18 Nov 2022, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-11-18 22:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-41884

Mitre link : CVE-2022-41884

CVE.ORG link : CVE-2022-41884


JSON object : View

Products Affected

google

  • tensorflow
CWE
CWE-670

Always-Incorrect Control Flow Implementation