CVE-2022-35990: `CHECK` fail in `FakeQuantWithMinMaxVarsPerChannelGradient` in TensorFlow
TensorFlow is an open source platform for machine learning. When tf.quantization.fakequantwithminmaxvarsperchannelgradient receives input min or max of rank other than 1, it gives a CHECK fail that can trigger a denial of service attack. We have patched the issue in GitHub commit f3cf67ac5705f4f04721d15e485e192bb319feed. The fix will be included in TensorFlow 2.10.0. We will also cherrypick this commit on TensorFlow 2.9.1, TensorFlow 2.8.1, and TensorFlow 2.7.2, as these are also affected and still in supported range.There are no known workarounds for this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-35990?
CVE-2022-35990 poses a risk of denial of service due to a CHECK fail when invalid input is processed.
How do I fix CVE-2022-35990?
To mitigate CVE-2022-35990, update TensorFlow to versions beyond 2.10-rc3, which include the security patch.
Which versions of TensorFlow are affected by CVE-2022-35990?
CVE-2022-35990 affects TensorFlow versions up to 2.10-rc3, including specific versions earlier than 2.8.1.
What functionality is impacted by CVE-2022-35990?
CVE-2022-35990 specifically impacts the `tf.quantization.fake_quant_with_min_max_vars_per_channel_gradient` operation.
Can CVE-2022-35990 be exploited remotely?
Yes, CVE-2022-35990 can potentially be exploited remotely, leading to a denial of service.