CVE-2022-36013: Null-dereference in `mlir::tfg::GraphDefImporter::ConvertNodeDef` in TensorFlow
TensorFlow is an open source platform for machine learning. When mlir::tfg::GraphDefImporter::ConvertNodeDef tries to convert NodeDefs without an op name, it crashes. We have patched the issue in GitHub commit a0f0b9a21c9270930457095092f558fbad4c03e5. The fix will be included in TensorFlow 2.10.0. We will also cherrypick this commit on TensorFlow 2.9.1, TensorFlow 2.8.1, and TensorFlow 2.7.2, as these are also affected and still in supported range. There are no known workarounds for this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-36013?
CVE-2022-36013 is a vulnerability in TensorFlow that can cause a crash when converting NodeDefs without an op name.
How severe is CVE-2022-36013?
CVE-2022-36013 has a severity score of 7.5, which is considered high.
Which versions of TensorFlow are affected by CVE-2022-36013?
TensorFlow versions 2.7.2 to 2.9.1 are affected by CVE-2022-36013.
How can I fix CVE-2022-36013?
The vulnerability has been patched in TensorFlow 2.10.0, so updating to this version will fix the issue.
Where can I find more information about CVE-2022-36013?
You can find more information about CVE-2022-36013 on the GitHub pages for TensorFlow and the associated security advisories.