CVE-2022-29203: Integer overflow in `SpaceToBatchND` in TensorFlow
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of tf.rawops.SpaceToBatchND (in all backends such as XLA and handwritten kernels) is vulnerable to an integer overflow: The result of this integer overflow is used to allocate the output tensor, hence we get a denial of service via a CHECK-failure (assertion failure), as in TFSA-2021-198. Versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4 contain a patch for this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-29203?
CVE-2022-29203 is considered to have a high severity due to its integer overflow vulnerability that can lead to potential exploitation.
How do I fix CVE-2022-29203?
To fix CVE-2022-29203, update to TensorFlow versions 2.9.0, 2.8.1, 2.7.2, or 2.6.4 or later.
Which versions of TensorFlow are affected by CVE-2022-29203?
CVE-2022-29203 affects TensorFlow versions prior to 2.9.0, including 2.8.1, 2.7.2, and 2.6.4.
What is the impact of CVE-2022-29203?
The impact of CVE-2022-29203 includes the potential for arbitrary code execution through the exploitation of an integer overflow in the SpaceToBatchND operation.
Are all TensorFlow backends affected by CVE-2022-29203?
Yes, all TensorFlow backends including XLA and handwritten kernels are affected by CVE-2022-29203.