CVE-2022-29193: Missing validation causes `TensorSummaryV2` in TensorFlow to crash
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of tf.rawops.TensorSummaryV2 does not fully validate the input arguments. This results in a CHECK-failure which can be used to trigger a denial of service attack. Versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4 contain a patch for this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-29193?
CVE-2022-29193 has a severity rating that could allow for denial of service through a CHECK failure.
How do I fix CVE-2022-29193?
To fix CVE-2022-29193, update TensorFlow to versions 2.9.0, 2.8.1, 2.7.2, or 2.6.4 and ensure proper input argument validation.
What software is affected by CVE-2022-29193?
CVE-2022-29193 affects TensorFlow versions prior to 2.9.0 including 2.8.1, 2.7.2, and 2.6.4.
What is the impact of exploiting CVE-2022-29193?
Exploiting CVE-2022-29193 can lead to a denial of service due to a CHECK failure from unvalidated input arguments.
Where can I find more information about CVE-2022-29193?
For more information on CVE-2022-29193, check the official TensorFlow repository and release notes.