CVE-2022-41907: Overflow in `ResizeNearestNeighborGrad` in Tensorflow
TensorFlow is an open source platform for machine learning. When tf.rawops.ResizeNearestNeighborGrad is given a large size input, it overflows. We have patched the issue in GitHub commit 00c821af032ba9e5f5fa3fe14690c8d28a657624. The fix will be included in TensorFlow 2.11. We will also cherrypick this commit on TensorFlow 2.10.1, 2.9.3, and TensorFlow 2.8.4, as these are also affected and still in supported range.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TensorFlowto a version that resolves this vulnerability.Fixed in 2.11 - Upgrade
Upgrade
TensorFlowto a version that resolves this vulnerability.Fixed in 2.10.1 - Upgrade
Upgrade
TensorFlowto a version that resolves this vulnerability.Fixed in 2.9.3 - Upgrade
Upgrade
TensorFlowto a version that resolves this vulnerability.Fixed in 2.8.4 - Upgrade
Upgrade
TensorFlowto a version that resolves this vulnerability.Patch 00c821af032ba9e5f5fa3fe14690c8d28a657624
Event History
Frequently Asked Questions
What is CVE-2022-41907?
CVE-2022-41907 is a vulnerability in TensorFlow where the tf.raw_ops.ResizeNearestNeighborGrad function can overflow when given a large size input.
What is the severity of CVE-2022-41907?
CVE-2022-41907 has a severity rating of 7.5 (high).
How does CVE-2022-41907 affect Google TensorFlow?
CVE-2022-41907 affects Google TensorFlow versions up to 2.10.1.
How can I fix CVE-2022-41907?
The issue has been patched in GitHub commit 00c821af032ba9e5f5fa3fe14690c8d28a657624 and the fix will be included in TensorFlow 2.11.
Where can I find more information about CVE-2022-41907?
More information about CVE-2022-41907 can be found in the TensorFlow GitHub repository and the associated security advisory.