CVE-2022-41883Out-of-bounds Read in Intel Optimization FOR Tensorflow

CWE-125Out-of-bounds Read5 documents5 sources
Severity
7.5HIGHNVD
CNA6.8
EPSS
0.2%
top 61.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 18
Latest updateNov 21

Description

TensorFlow is an open source platform for machine learning. When ops that have specified input sizes receive a differing number of inputs, the executor will crash. We have patched the issue in GitHub commit f5381e0e10b5a61344109c1b7c174c68110f7629. The fix will be included in TensorFlow 2.11. We will also cherrypick this commit on TensorFlow 2.10.1, 2.9.3, and TensorFlow 2.8.4, as these are also affected and still in supported range.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

PyPIintel/optimization_for_tensorflow2.10.02.10.1
NVDgoogle/tensorflow2.10.0
CVEListV5tensorflow/tensorflow>= 2.10.0, < 2.10.1

Patches

🔴Vulnerability Details

3
GHSA
Out of bounds segmentation fault due to unequal op inputs in Tensorflow2022-11-21
OSV
Out of bounds segmentation fault due to unequal op inputs in Tensorflow2022-11-21
CVEList
Out of bounds segmentation fault due to unequal op inputs in Tensorflow2022-11-18

📋Vendor Advisories

1
Debian
CVE-2022-41883: tensorflow - TensorFlow is an open source platform for machine learning. When ops that have s...2022
CVE-2022-41883 — Out-of-bounds Read in Intel | cvebase