CVE-2022-35966: Segfault in `QuantizedAvgPool` in TensorFlow
TensorFlow is an open source platform for machine learning. If QuantizedAvgPool is given mininput or maxinput tensors of a nonzero rank, it results in a segfault that can be used to trigger a denial of service attack. We have patched the issue in GitHub commit 7cdf9d4d2083b739ec81cfdace546b0c99f50622. The fix will be included in TensorFlow 2.10.0. We will also cherrypick this commit on TensorFlow 2.9.1, TensorFlow 2.8.1, and TensorFlow 2.7.2, as these are also affected and still in supported range. There are no known workarounds for this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-35966?
CVE-2022-35966 is classified as a denial of service vulnerability due to the potential for a segfault.
How do I fix CVE-2022-35966?
To fix CVE-2022-35966, update TensorFlow to a patched version released after commit 7cdf9d4d2083b739ec81cfdace546b0c99f50622.
Which versions of TensorFlow are affected by CVE-2022-35966?
CVE-2022-35966 affects TensorFlow versions from 2.7.0 to 2.7.2, 2.8.0 to 2.8.1, 2.9.0 to 2.9.1, and certain release candidates of 2.10.
What attack vector does CVE-2022-35966 provide?
CVE-2022-35966 can be exploited to create a denial of service by causing a segfault in the application.
Who is the vendor of the software affected by CVE-2022-35966?
The vendor of the software affected by CVE-2022-35966 is Google, specifically their TensorFlow platform.