cbcvebase.
CVE-2022-41893
published 2022-11-18

CVE-2022-41893: TensorFlow is an open source platform for machine learning. If `tf.raw_ops.TensorListResize` is given a nonscalar value for input `size`, it results `CHECK`…

PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.44%
36.0th percentile
TensorFlow is an open source platform for machine learning. If `tf.raw_ops.TensorListResize` is given a nonscalar value for input `size`, it results `CHECK` fail which can be used to trigger a denial of service attack. We have patched the issue in GitHub commit 888e34b49009a4e734c27ab0c43b0b5102682c56. The fix will be included in TensorFlow 2.11. We will also cherrypick this commit on TensorFlow 2.10.1, 2.9.3, and TensorFlow 2.8.4, as these are also affected and still in supported range.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiantensorflow
googletensorflow< 2.8.42.8.4
googletensorflow>= 2.10.0 < 2.10.12.10.1
googletensorflow>= 2.9.0 < 2.9.32.9.3
inteloptimization_for_tensorflow>= 0 < 2.8.42.8.4
inteloptimization_for_tensorflow>= 2.10.0 < 2.10.12.10.1
inteloptimization_for_tensorflow>= 2.9.0 < 2.9.32.9.3
msrccbl2_tensorflow_2.11.0-1_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
tensorflowtensorflow< 2.8.42.8.4
tensorflowtensorflow
tensorflowtensorflow

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_msrc7.5HIGH
vendor_debian4.8LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.