CVE-2022-41890: `CHECK` fail in `BCast` overflow in Tensorflow
TensorFlow is an open source platform for machine learning. If BCast::ToShape is given input larger than an int32, it will crash, despite being supposed to handle up to an int64. An example can be seen in tf.experimental.numpy.outer by passing in large input to the input b. We have patched the issue in GitHub commit 8310bf8dd188ff780e7fc53245058215a05bdbe5. The fix will be included in TensorFlow 2.11. We will also cherrypick this commit on TensorFlow 2.10.1, 2.9.3, and TensorFlow 2.8.4, as these are also affected and still in supported range.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TensorFlowto a version that resolves this vulnerability.Fixed in 2.11Patch 8310bf8dd188ff780e7fc53245058215a05bdbe5 - Upgrade
Upgrade
TensorFlowto a version that resolves this vulnerability.Fixed in 2.10.1Patch 8310bf8dd188ff780e7fc53245058215a05bdbe5 - Upgrade
Upgrade
TensorFlowto a version that resolves this vulnerability.Fixed in 2.9.3Patch 8310bf8dd188ff780e7fc53245058215a05bdbe5 - Upgrade
Upgrade
TensorFlowto a version that resolves this vulnerability.Fixed in 2.8.4Patch 8310bf8dd188ff780e7fc53245058215a05bdbe5
Event History
Frequently Asked Questions
What is CVE-2022-41890?
CVE-2022-41890 is a vulnerability in TensorFlow, an open source platform for machine learning, where the `BCast::ToShape` function crashes when given input larger than an `int32`, despite being expected to handle up to an `int64`.
What is the severity of CVE-2022-41890?
CVE-2022-41890 has a severity rating of high with a score of 7.5.
How does CVE-2022-41890 affect Google TensorFlow?
CVE-2022-41890 affects Google TensorFlow versions up to and including 2.8.4, 2.9.0 to 2.9.3, and 2.10.0 to 2.10.1.
How can I fix CVE-2022-41890?
To fix CVE-2022-41890, update your Google TensorFlow installation to version 2.8.5, 2.9.4, or 2.10.2, which contain the necessary patches.
Where can I find more information about CVE-2022-41890?
You can find more information about CVE-2022-41890 on the following GitHub pages: [1] [2] [3].