CVE-2022-35940: Int overflow in `RaggedRangeOp` in Tensoflow
TensorFlow is an open source platform for machine learning. The RaggedRangOp function takes an argument limits that is eventually used to construct a TensorShape as an int64. If limits is a very large float, it can overflow when converted to an int64. This triggers an InvalidArgument but also throws an abort signal that crashes the program. We have patched the issue in GitHub commit 37cefa91bee4eace55715eeef43720b958a01192. The fix will be included in TensorFlow 2.10.0. We will also cherrypick this commit on TensorFlow 2.9.1, TensorFlow 2.8.1, and TensorFlow 2.7.2, as these are also affected and still in supported range. There are no known workarounds for this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-35940?
CVE-2022-35940 is classified as a high severity vulnerability due to the potential for overflow resulting in incorrect computations.
How do I fix CVE-2022-35940?
To mitigate CVE-2022-35940, upgrade to TensorFlow versions 2.7.3, 2.8.2, 2.9.2, or 2.10 after the release candidates.
Which TensorFlow versions are affected by CVE-2022-35940?
CVE-2022-35940 affects TensorFlow versions 2.7.0 to 2.7.2, 2.8.0 to 2.8.1, and 2.9.0 to 2.9.1, along with specific release candidates of 2.10.
What specific function is vulnerable in CVE-2022-35940?
The vulnerability in CVE-2022-35940 resides in the `RaggedRangOp` function when handling large float arguments.
Is CVE-2022-35940 injectable through user input?
Yes, CVE-2022-35940 can be exploited using user input to manipulate the limits parameter in the `RaggedRangOp` function.