First published: Fri Nov 18 2022(Updated: )
TensorFlow is an open source platform for machine learning. If `MirrorPadGrad` is given outsize input `paddings`, TensorFlow will give a heap OOB error. We have patched the issue in GitHub commit 717ca98d8c3bba348ff62281fdf38dcb5ea1ec92. The fix will be included in TensorFlow 2.11. We will also cherrypick this commit on TensorFlow 2.10.1, 2.9.3, and TensorFlow 2.8.4, as these are also affected and still in supported range.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google TensorFlow | <2.8.4 | |
Google TensorFlow | >=2.9.0<2.9.3 | |
Google TensorFlow | >=2.10.0<2.10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this TensorFlow vulnerability is CVE-2022-41895.
The severity rating of CVE-2022-41895 is high with a value of 7.5.
The affected software for CVE-2022-41895 is versions 2.8.4, 2.9.0 to 2.9.3, and 2.10.0 to 2.10.1 of Google TensorFlow.
To fix the CVE-2022-41895 vulnerability, update TensorFlow to version 2.11 or later.
You can find more information about CVE-2022-41895 on the GitHub page [linking to the respective advisory].