CVE-2022-21734: `CHECK`-failures in Tensorflow
Impact The implementation of MapStage is vulnerable a CHECK-fail if the key tensor is not a scalar:
python import tensorflow as tf import numpy as np
tf.rawops.MapStage( key = tf.constant(value=[4], shape= (1,2), dtype=tf.int64), indices = np.array([[6]]), values = np.array([-60]), dtypes = [tf.int64], capacity=0, memorylimit=0, container='', sharedname='', name=None )
Patches We have patched the issue in GitHub commit f57315566d7094f322b784947093406c2aea0d7d.
The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow 2.6.3, and TensorFlow 2.5.3, as these are also affected and still in supported range.
For more information Please consult our security guide for more information regarding the security model and how to contact us with issues and questions.
Attribution This vulnerability has been reported by Faysal Hossain Shezan from University of Virginia. ~
Other sources
Tensorflow is an Open Source Machine Learning Framework. The implementation of MapStage is vulnerable a CHECK-fail if the key tensor is not a scalar. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow 2.6.3, and TensorFlow 2.5.3, as these are also affected and still in supported range.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-21734?
CVE-2022-21734 has been assigned a severity level that indicates a potential crash due to a CHECK-fail if the key tensor is not a scalar.
How do I fix CVE-2022-21734?
To fix CVE-2022-21734, update TensorFlow to version 2.7.1 or later.
Which versions of TensorFlow are affected by CVE-2022-21734?
CVE-2022-21734 affects TensorFlow versions up to 2.5.2, versions between 2.6.0 to 2.6.2, and version 2.7.0.
What kind of issue does CVE-2022-21734 present?
CVE-2022-21734 presents an issue where a CHECK-fail occurs when a non-scalar key tensor is used.
Is there a workaround for CVE-2022-21734?
There are no documented workarounds for CVE-2022-21734; the only resolution is to update to a secure version.