Lucene search

K
cvelistGitHub_MCVELIST:CVE-2022-41887
HistoryNov 18, 2022 - 12:00 a.m.

CVE-2022-41887 Overflow in `tf.keras.losses.poisson` in Tensorflow

2022-11-1800:00:00
CWE-131
GitHub_M
www.cve.org
1
tensorflow
machine learning
overflow
poisson
binaryop
github
patch
commit
cherrypick
int32
size mismatch
crash
supported range

4.8 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

48.9%

TensorFlow is an open source platform for machine learning. tf.keras.losses.poisson receives a y_pred and y_true that are passed through functor::mul in BinaryOp. If the resulting dimensions overflow an int32, TensorFlow will crash due to a size mismatch during broadcast assignment. We have patched the issue in GitHub commit c5b30379ba87cbe774b08ac50c1f6d36df4ebb7c. The fix will be included in TensorFlow 2.11. We will also cherrypick this commit on TensorFlow 2.10.1 and 2.9.3, as these are also affected and still in supported range. However, we will not cherrypick this commit into TensorFlow 2.8.x, as it depends on Eigen behavior that changed between 2.8 and 2.9.

CNA Affected

[
  {
    "vendor": "tensorflow",
    "product": "tensorflow",
    "versions": [
      {
        "version": ">= 2.10.0, < 2.10.1",
        "status": "affected"
      },
      {
        "version": "< 2.9.3",
        "status": "affected"
      }
    ]
  }
]

4.8 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

48.9%

Related for CVELIST:CVE-2022-41887