CVE-2022-23564: Reachable Assertion in Tensorflow
Impact When decoding a resource handle tensor from protobuf, a TensorFlow process can encounter cases where a CHECK assertion is invalidated based on user controlled arguments. This allows attackers to cause denial of services in TensorFlow processes.
Patches We have patched the issue in GitHub commit 14fea662350e7c26eb5fe1be2ac31704e5682ee6.
The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow 2.6.3, and TensorFlow 2.5.3, as these are also affected and still in supported range.
For more information Please consult our security guide for more information regarding the security model and how to contact us with issues and questions.
Other sources
Tensorflow is an Open Source Machine Learning Framework. When decoding a resource handle tensor from protobuf, a TensorFlow process can encounter cases where a CHECK assertion is invalidated based on user controlled arguments. This allows attackers to cause denial of services in TensorFlow processes. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow 2.6.3, and TensorFlow 2.5.3, as these are also affected and still in supported range.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23564?
CVE-2022-23564 has been classified as a denial of service vulnerability affecting TensorFlow.
How do I fix CVE-2022-23564?
To resolve CVE-2022-23564, upgrade TensorFlow to version 2.5.3, 2.6.3, or 2.7.1 or higher.
What affects CVE-2022-23564?
CVE-2022-23564 affects TensorFlow versions up to 2.5.2, between 2.6.0 and 2.6.2, and the specific version 2.7.0.
What is the impact of CVE-2022-23564?
The impact of CVE-2022-23564 is that it can lead to denial of service in TensorFlow processes due to invalidated CHECK assertions.
Who is responsible for fixing CVE-2022-23564?
The maintainers of TensorFlow, specifically Google, are responsible for addressing CVE-2022-23564 by issuing patches.