|
numpy
|
1.22.0
|
<1.22.2
|
show Numpy 1.22.2 includes a fix for CVE-2021-41495: Null Pointer Dereference vulnerability exists in numpy.sort in NumPy in the PyArray_DescrNew function due to missing return-value validation, which allows attackers to conduct DoS attacks by repetitively creating sort arrays.
NOTE: While correct that validation is missing, an error can only occur due to an exhaustion of memory. If the user can exhaust memory, they are already privileged. Further, it should be practically impossible to construct an attack which can target the memory exhaustion to occur at exactly this place.
NOTE2: The specs we include in this advisory differ from the publicly available on other sources. For example, the advisory posted by the NVD indicate that versions up to and including 1.19.0 are affected. However, research by Safety CLI Cybersecurity confirms that the vulnerability remained unaddressed until version 1.22.2.
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35992: 'CHECK' fail in 'TensorListFromTensor'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-9v8w-xmr4-wgxp
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35999: 'CHECK' fail in 'Conv2DBackpropInput'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-37jf-mjv6-xfqw
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-36018: 'CHECK' fail in 'RaggedTensorToVariant'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-m6cv-4fmf-66xf
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 update 'curl' to v7.83.1 to handle CVE-2022-27775.
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 update 'curl' to v7.83.1 to handle CVE-2022-27778.
|
|
tensorflow
|
2.5.3
|
<2.11.1 ,
>=2.12.0rc0,<2.12.0
|
show Tensorflow 2.11.1 and 2.12.0 include a fix for CVE-2023-25658: Prior to versions 2.12.0 and 2.11.1, an out of bounds read is in GRUBlockCellGrad.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-68v3-g9cm-rmm6
|
|
tensorflow
|
2.5.3
|
<2.8.4 ,
>=2.9.0rc0,<2.9.3 ,
>=2.10.0rc0,<2.10.1
|
show Tensorflow 2.8.4, 2.9.3 and 2.10.1 include a fix for CVE-2022-41907: When 'tf.raw_ops.ResizeNearestNeighborGrad' is given a large 'size' input, it overflows.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-368v-7v32-52fx
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 include a fix for CVE-2022-29203: Integer overflow in 'SpaceToBatchND'.
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 include a fix for CVE-2022-29198: Missing validation which causes denial of service via 'SparseTensorToCSRSparseMatrix'.
|
|
tensorflow
|
2.5.3
|
<2.8.4 ,
>=2.9.0rc0,<2.9.3 ,
>=2.10.0rc0,<2.10.1 ,
>=2.11.0rc0,<2.11.0
|
show TensorFlow 2.8.4, 2.9.3, 2.10.1 and 2.11.0 include a fix for CVE-2022-35935: 'CHECK' failure in 'SobolSample' via missing validation.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-97p7-w86h-vcf9
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-cqvq-fvhr-v6hc
|
|
tensorflow
|
2.5.3
|
<2.11.1 ,
>=2.12.0rc0,<2.12.0
|
show Tensorflow 2.11.1 and 2.12.0 include a fix for CVE-2023-25665: Prior to versions 2.12.0 and 2.11.1, when 'SparseSparseMaximum' is given invalid sparse tensors as inputs, it can give a null pointer error.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-558h-mq8x-7q9g
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 include a fix for CVE-2022-29205: Segfault due to missing support for quantized types.
|
|
tensorflow
|
2.5.3
|
<2.8.4 ,
>=2.10.0,<2.10.1 ,
>=2.9.0,<2.9.3
|
show Impact: A recurring instance of CVE-2022-35935 has been observed and addressed. In this case, `SobolSample` is prone to denial of service due to assumed scalar inputs. You can replicate this using the following code in Python:
```python
import tensorflow as tf
tf.raw_ops.SobolSample(dim=tf.constant([1,0]), num_results=tf.constant([1]), skip=tf.constant([1]))
```
Patches: Corrective measures have been taken and the issue has been patched via GitHub commits c65c67f88ad770662e8f191269a907bf2b94b1bf and 02400ea266bd811fc016a848445de1bbff3a23a0. These fixes will be integrated in the forthcoming TensorFlow 2.11 release and will also be added to TensorFlow 2.10.1, 2.9.3, and 2.8.4 as they fall within the supported range. Furthermore, the initial commit will be incorporated into TensorFlow 2.7.4.
For more information: You can refer to the TensorFlow's security guide for comprehensive insights into the security model and for details on how to contact them for queries or issues.
Attribution: This vulnerability was reported by Kang Hong Jin from Singapore Management University, Neophytos Christou from Secure Systems Labs at Brown University, Liu Liyuan from the Information System & Security and Countermeasures Experiments Center at Beijing Institute of Technology, and Pattarakrit Rattankul.
|
|
tensorflow
|
2.5.3
|
<2.11.1 ,
>=2.12.0rc0,<2.12.0
|
show Tensorflow 2.11.1 and 2.12.0 include a fix for CVE-2023-25676: When running versions prior to 2.12.0 and 2.11.1 with XLA, 'tf.raw_ops.ParallelConcat' segfaults with a nullptr dereference when given a parameter 'shape' with rank that is not greater than zero.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-6wfh-89q8-44jq
|
|
tensorflow
|
2.5.3
|
<2.8.4 ,
>=2.9.0rc0,<2.9.3 ,
>=2.10.0rc0,<2.10.1
|
show Tensorflow 2.8.4, 2.9.3 and 2.10.1 include a fix for CVE-2022-41900: The security vulnerability results in FractionalMax(AVG)Pool with illegal pooling_ratio. Attackers using Tensorflow can exploit the vulnerability. They can access heap memory which is not in the control of user, leading to a crash or remote code execution.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-xvwp-h6jv-7472
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 include a fix for CVE-2022-29197: Missing validation which causes denial of service via 'UnsortedSegmentJoin'.
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 include a fix for CVE-2022-29213: Crashes stemming from incomplete validation in signal ops.
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35937: OOB read in 'Gather_nd' op in TF Lite.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-pxrw-j2fv-hx3h
|
|
tensorflow
|
2.5.3
|
<2.14.1
|
show TensorFlow updates its curl dependency from version 8.2.1 to 8.4.0 to address CVE-2023-38546.
|
|
tensorflow
|
2.5.3
|
<2.8.4 ,
>=2.10.0,<2.10.1 ,
>=2.9.0,<2.9.3
|
show The effect of CVE-2022-35991 was seen once more, where TensorListScatter and TensorListScatterV2 could potentially crash due to non scalar inputs in the element_shape parameter while in eager mode. This issue has been identified and resolved. The issue was identified when the following Python code was executed:
```python
import tensorflow as tf
arg_0=tf.random.uniform(shape=(2, 2, 2), dtype=tf.float16, maxval=None)
arg_1=tf.random.uniform(shape=(2, 2, 2), dtype=tf.int32, maxval=65536)
arg_2=tf.random.uniform(shape=(2, 2, 2), dtype=tf.int32, maxval=65536)
arg_3=''
tf.raw_ops.TensorListScatter(tensor=arg_0, indices=arg_1, element_shape=arg_2, name=arg_3)
```
A patch to resolve this issue is available in the GitHub commit bf9932fc907aff0e9e8cccf769e8b00d30fd81a1. This fix will be part of TensorFlow 2.11. Additionally, the commitment will be selected for TensorFlow 2.10.1, 2.9.3, and TensorFlow 2.8.4, as these versions are also known to be affected and still under supported range.
For further details, please refer to TensorFlow's security guide. If there is any issue or question, contact us please.
The person who brought this vulnerability to our attention is Pattarakrit Rattankul.
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35934: 'CHECK' failure in tf.reshape via overflows.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-f4w6-h4f5-wx45
|
|
tensorflow
|
2.5.3
|
<2.11.1 ,
>=2.12.0rc0,<2.12.0
|
show Tensorflow 2.11.1 and 2.12.0 include a fix for CVE-2023-25660: Prior to versions 2.12.0 and 2.11.1, when the parameter 'summarize' of 'tf.raw_ops.Print' is zero, the new method 'SummarizeArray<bool>' will reference to a nullptr, leading to a seg fault.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-qjqc-vqcf-5qvj
|
|
tensorflow
|
2.5.3
|
<2.11.1 ,
>=2.12.0rc0,<2.12.0
|
show Tensorflow 2.11.1 and 2.12.0 include a fix for CVE-2023-25663: Prior to versions 2.12.0 and 2.11.1, when 'ctx->step_containter()' is a null ptr, the Lookup function will be executed with a null pointer.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-64jg-wjww-7c5w
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 include a fix for CVE-2022-29212: Core dump when loading TFLite models with quantization.
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-36011: Null dereference on MLIR on empty function attributes.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-fv43-93gv-vm8f
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 update 'curl' to v7.83.1 to handle CVE-2022-27776.
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35940: Int overflow in 'RaggedRangeOp'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-x989-q2pq-4q5x
|
|
tensorflow
|
2.5.3
|
<2.11.1 ,
>=2.12.0rc0,<2.12.0
|
show Tensorflow 2.11.1 and 2.12.0 include a fix for CVE-2023-25667: Prior to versions 2.12.0 and 2.11.1, integer overflow occurs when '2^31 <= num_frames * height * width * channels < 2^32', for example Full HD screencast of at least 346 frames.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-fqm2-gh8w-gr68
|
|
tensorflow
|
2.5.3
|
<2.8.4 ,
>=2.9.0rc0,<2.9.3 ,
>=2.10.0rc0,<2.10.1
|
show Tensorflow 2.8.4, 2.9.3 and 2.10.1 include a fix for CVE-2022-41894: The reference kernel of the 'CONV_3D_TRANSPOSE' TensorFlow Lite operator wrongly increments the data_ptr when adding the bias to the result. Instead of 'data_ptr += num_channels;' it should be 'data_ptr += output_num_channels;' as if the number of input channels is different than the number of output channels, the wrong result will be returned and a buffer overflow will occur if num_channels > output_num_channels. An attacker can craft a model with a specific number of input channels. It is then possible to write specific values through the bias of the layer outside the bounds of the buffer. This attack only works if the reference kernel resolver is used in the interpreter.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-h6q3-vv32-2cq5
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-36004: 'CHECK' fail in 'tf.random.gamma'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-mv8m-8x97-937q
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 update 'curl' to v7.83.1 to handle CVE-2022-27780.
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-36012: Assertion fail on MLIR empty edge names.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-jvhc-5hhr-w3v5
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35959: 'CHECK' failures in 'AvgPool3DGrad'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-wxjj-cgcx-r3vq
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 update 'curl' to v7.83.1 to handle CVE-2022-30115.
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 include a fix for CVE-2022-29194: Missing validation which causes denial of service via 'DeleteSessionTensor'.
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 include a fix for CVE-2022-29196: Missing validation which causes denial of service via 'Conv3DBackpropFilterV2'.
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35997: 'CHECK' fail in 'tf.sparse.cross'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-p7hr-f446-x6qf
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 update 'zlib' to v1.2.12 to handle CVE-2018-25032.
|
|
tensorflow
|
2.5.3
|
<2.8.4 ,
>=2.9.0rc0,<2.9.3 ,
>=2.10.0rc0,<2.10.1
|
show Tensorflow 2.8.4, 2.9.3 and 2.10.1 include a fix for CVE-2022-41885: When 'tf.raw_ops.FusedResizeAndPadConv2D' is given a large tensor shape, it overflows.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-762h-vpvw-3rcx
|
|
tensorflow
|
2.5.3
|
<2.8.4 ,
>=2.9.0rc0,<2.9.3 ,
>=2.10.0rc0,<2.10.1
|
show Tensorflow 2.8.4, 2.9.3 and 2.10.1 include a fix for CVE-2022-41910: The function MakeGrapplerFunctionItem takes arguments that determine the sizes of inputs and outputs. If the inputs given are greater than or equal to the sizes of the outputs, an out-of-bounds memory read or a crash is triggered.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-frqp-wp83-qggv
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 include a fix for CVE-2022-29209: Type confusion leading to 'CHECK'-failure based denial of service.
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35964: Segfault in 'BlockLSTMGradV2'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-f7r5-q7cx-h668
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 update 'curl' to v7.83.1 to handle CVE-2022-27782.
|
|
tensorflow
|
2.5.3
|
<2.8.4 ,
>=2.9.0rc0,<2.9.3 ,
>=2.10.0rc0,<2.10.1
|
show Tensorflow 2.8.4, 2.9.3 and 2.10.1 include a fix for CVE-2022-41898: If 'SparseFillEmptyRowsGrad' is given empty inputs, TensorFlow will crash.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-hq7g-wwwp-q46h
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 include a fix for CVE-2022-29202: Denial of service in 'tf.ragged.constant' due to lack of validation.
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35979: Segfault in 'QuantizedRelu' and 'QuantizedRelu6'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-v7vw-577f-vp8x
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 include a fix for CVE-2022-29193: missing validation which causes 'TensorSummaryV2' to crash.
|
|
tensorflow
|
2.5.3
|
<2.11.1 ,
>=2.12.0rc0,<2.12.0
|
show Tensorflow 2.11.1 and 2.12.0 include a fix for CVE-2023-25675: When running versions prior to 2.12.0 and 2.11.1 with XLA, 'tf.raw_ops.Bincount' segfaults when given a parameter 'weights' that is neither the same shape as parameter 'arr' nor a length-0 tensor.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-7x4v-9gxg-9hwj
|
|
tensorflow
|
2.5.3
|
<2.11.1 ,
>=2.12.0rc0,<2.12.0
|
show Tensorflow 2.11.1 and 2.12.0 include a fix for CVE-2023-25672: The function 'tf.raw_ops.LookupTableImportV2' cannot handle scalars in the 'values' parameter and gives an NPE. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 include a fix for CVE-2022-29195: Missing validation which causes denial of service via 'StagePeek'.
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35995: 'CHECK' fail in 'AudioSummaryV2'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-g9h5-vr8m-x2h4
|
|
tensorflow
|
2.5.3
|
<2.8.4 ,
>=2.9.0rc0,<2.9.3 ,
>=2.10.0rc0,<2.10.1
|
show Tensorflow 2.8.4, 2.9.3 and 2.10.1 include a fix for CVE-2022-41908: TensorFlow is an open source platform for machine learning. An input 'token' that is not a UTF-8 bytestring will trigger a 'CHECK' fail in 'tf.raw_ops.PyFunc'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-mv77-9g28-cwg3
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35965: Segfault in 'LowerBound' and 'UpperBound'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-qxpx-j395-pw36
|
|
tensorflow
|
2.5.3
|
<2.8.4 ,
>=2.9.0rc0,<2.9.3 ,
>=2.10.0rc0,<2.10.1
|
show Tensorflow 2.8.4, 2.9.3 and 2.10.1 include a fix for CVE-2022-41911: When printing a tensor, we get it's data as a 'const char*' array (since that's the underlying storage) and then we typecast it to the element type. However, conversions from 'char' to 'bool' are undefined if the 'char' is not '0' or '1', so sanitizers/fuzzers will crash.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-pf36-r9c6-h97j
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 include a fix for CVE-2022-29199: Missing validation which causes denial of service via 'LoadAndRemapMatrix'.
|
|
tensorflow
|
2.5.3
|
<2.8.4 ,
>=2.9.0rc0,<2.9.3 ,
>=2.10.0rc0,<2.10.1
|
show Tensorflow 2.8.4, 2.9.3 and 2.10.1 include a fix for CVE-2022-41899: TensorFlow is an open source platform for machine learning. Inputs 'dense_features' or 'example_state_data' not of rank 2 will trigger a 'CHECK' fail in 'SdcaOptimizer'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-27rc-728f-x5w2
|
|
tensorflow
|
2.5.3
|
<2.11.1 ,
>=2.12.0rc0,<2.12.0
|
show Tensorflow 2.11.1 and 2.12.0 include a fix for CVE-2023-27579: Constructing a tflite model with a paramater 'filter_input_channel' of less than 1 gives a FPE.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-5w96-866f-6rm8
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35982: Segfault in 'SparseBincount'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-397c-5g2j-qxpv
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-36026: 'CHECK' fail in 'QuantizeAndDequantizeV3'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-9cr2-8pwr-fhfq
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35998: 'CHECK' fail in 'EmptyTensorList'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-qhw4-wwr7-gjc5
|
|
tensorflow
|
2.5.3
|
<2.8.4 ,
>=2.9.0rc0,<2.9.3 ,
>=2.10.0rc0,<2.10.1
|
show Tensorflow 2.8.4, 2.9.3 and 2.10.1 include a fix for CVE-2022-41895: If 'MirrorPadGrad' is given outsize input 'paddings', TensorFlow will give a heap OOB error.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-gq2j-cr96-gvqx
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35988: 'CHECK' fail in 'tf.linalg.matrix_rank'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-9vqj-64pv-w55c
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35983: 'CHECK' fail in 'Save' and 'SaveSlices'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-m6vp-8q9j-whx4
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 include a fix for CVE-2022-29200: Missing validation which causes denial of service via 'LSTMBlockCell'.
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-36014: Null-dereference in 'mlir::tfg::TFOp::nameAttr'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-7j3m-8g3c-9qqq
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35972: Segfault in 'QuantizedBiasAdd'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-4pc4-m9mj-v2r9
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35963: 'CHECK' failures in 'FractionalAvgPoolGrad'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-84jm-4cf3-9jfm
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-36017: Segfault in 'Requantize'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-wqmc-pm8c-2jhc
|
|
tensorflow
|
2.5.3
|
<2.8.4 ,
>=2.9.0rc0,<2.9.3 ,
>=2.10.0rc0,<2.10.1
|
show Tensorflow 2.8.4, 2.9.3 and 2.10.1 include a fix for CVE-2022-41880: When the 'BaseCandidateSamplerOp' function receives a value in 'true_classes' larger than 'range_max', a heap oob read occurs.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-8w5g-3wcv-9g2j
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35941: 'CHECK' failure in 'AvgPoolOp'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-mgmh-g2v6-mqw5
|
|
tensorflow
|
2.5.3
|
<2.11.1 ,
>=2.12.0rc0,<2.12.0
|
show Tensorflow 2.11.1 and 2.12.0 include a fix for CVE-2023-25670: Versions prior to 2.12.0 and 2.11.1 have a null point error in QuantizedMatMulWithBiasAndDequantize with MKL enabled.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-49rq-hwc3-x77w
|
|
tensorflow
|
2.5.3
|
<2.7.2 ,
>=2.8.0,<2.8.1 ,
>=2.9.0,<2.9.1
|
show A vulnerability in TensorFlow's `GatherNd` function can trigger an out-of-bounds memory read or crash when inputs exceed output sizes. This issue is resolved in a GitHub commit, which will be included in an upcoming TensorFlow release. Additionally, the fix will be applied to several previous versions that are still under support. This vulnerability has no known workarounds, so updating to a patched version is recommended.
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 include a fix for CVE-2022-29216: Code injection in 'saved_model_cli'.
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35993: 'CHECK' fail in 'SetSize'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-wq6q-6m32-9rv9
|
|
tensorflow
|
2.5.3
|
<2.8.4 ,
>=2.9.0rc0,<2.9.3 ,
>=2.10.0rc0,<2.10.1
|
show Tensorflow 2.8.4, 2.9.3 and 2.10.1 include a fix for CVE-2022-41897: If 'FractionMaxPoolGrad' is given outsize inputs 'row_pooling_sequence' and 'col_pooling_sequence', TensorFlow will crash.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-f2w8-jw48-fr7j
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35971: 'CHECK' fail in 'FakeQuantWithMinMaxVars'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-9fpg-838v-wpv7
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-36019: 'CHECK' fail in 'FakeQuantWithMinMaxVarsPerChannel'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-9j4v-pp28-mxv7
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 include a fix for CVE-2022-29211: Segfault when 'tf.histogram_fixed_width' is called with NaN values.
|
|
tensorflow
|
2.5.3
|
<2.8.4 ,
>=2.9.0rc0,<2.9.3 ,
>=2.10.0rc0,<2.10.1
|
show Tensorflow 2.8.4, 2.9.3 and 2.10.1 include a fix for CVE-2022-41890: If 'BCast::ToShape' is given input larger than an 'int32', it will crash, despite being supposed to handle up to an 'int64'. An example can be seen in 'tf.experimental.numpy.outer' by passing in large input to the input 'b'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-h246-cgh4-7475
|
|
tensorflow
|
2.5.3
|
<2.8.4 ,
>=2.9.0rc0,<2.9.3 ,
>=2.10.0rc0,<2.10.1
|
show TensorFlow is an open source platform for machine learning. An input 'sparse_matrix' that is not a matrix with a shape with rank 0 will trigger a 'CHECK' fail in 'tf.raw_ops.SparseMatrixNNZ'. We have patched the issue in GitHub commit f856d02e5322821aad155dad9b3acab1e9f5d693. The fix will be included in TensorFlow 2.11. We will also cherrypick this commit on TensorFlow 2.10.1, 2.9.3, and TensorFlow 2.8.4, as these are also affected and still in supported range.
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35973: Segfault in 'QuantizedMatMul'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-689c-r7h2-fv9v
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35968: 'CHECK' fail in 'AvgPoolGrad'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-2475-53vw-vp25
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 include a fix for CVE-2022-29192: missing validation which crashes 'QuantizeAndDequantizeV4Grad'.
|
|
tensorflow
|
2.5.3
|
<2.11.1 ,
>=2.12.0rc0,<2.12.0
|
show Tensorflow 2.11.1 and 2.12.0 include a fix for CVE-2023-25664: Prior to versions 2.12.0 and 2.11.1, there is a heap buffer overflow in TAvgPoolGrad.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-6hg6-5c2q-7rcr
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35939: OOB write in 'scatter_nd' op in TF Lite.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-ffjm-4qwc-7cmf
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35990: 'CHECK' fail in 'FakeQuantWithMinMaxVarsPerChannelGradient'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-h7ff-cfc9-wmmh
|
|
tensorflow
|
2.5.3
|
<2.11.1 ,
>=2.12.0rc0,<2.12.0
|
show Tensorflow 2.11.1 and 2.12.0 include a fix for CVE-2023-25671: There is out-of-bounds access due to mismatched integer type sizes.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-j5w9-hmfh-4cr6
|
|
tensorflow
|
2.5.3
|
<2.14.1
|
show TensorFlow 2.14.1 updates its curl dependency from version 8.2.1 to 8.4.0 to address CVE-2023-38545.
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-36027: Segfault TFLite converter on per-channel quantized transposed convolutions.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-79h2-q768-fpxr
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 include a fix for CVE-2022-29204: Missing validation which causes denial of service via 'Conv3DBackpropFilterV2'.
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-36005: 'CHECK' fail in 'FakeQuantWithMinMaxVarsGradient'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-r26c-679w-mrjm
|
|
tensorflow
|
2.5.3
|
<2.8.4 ,
>=2.9.0rc0,<2.9.3 ,
>=2.10.0rc0,<2.10.1
|
show Tensorflow 2.8.4, 2.9.3 and 2.10.1 include a fix for CVE-2022-41886: When 'tf.raw_ops.ImageProjectiveTransformV2' is given a large output shape, it overflows.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-54pp-c6pp-7fpx
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-36003: 'CHECK' fail in 'RandomPoissonV2'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-cv2p-32v3-vhwq
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35985: 'CHECK' fail in 'LRNGrad'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-9942-r22v-78cp
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 include a fix for CVE-2022-29191: Missing validation which causes denial of service via 'GetSessionTensor'.
|
|
tensorflow
|
2.5.3
|
<2.11.1 ,
>=2.12.0rc0,<2.12.0
|
show Tensorflow 2.11.1 and 2.12.0 include a fix for CVE-2023-25674: Versions prior to 2.12.0 and 2.11.1 have a null pointer error in RandomShuffle with XLA enabled.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-gf97-q72m-7579
|
|
tensorflow
|
2.5.3
|
<2.11.1 ,
>=2.12.0rc0,<2.12.0
|
show Tensorflow 2.11.1 and 2.12.0 include a fix for CVE-2023-25801: Prior to versions 2.12.0 and 2.11.1, 'nn_ops.fractional_avg_pool_v2' and 'nn_ops.fractional_max_pool_v2' require the first and fourth elements of their parameter 'pooling_ratio' to be equal to 1.0, as pooling on batch and channel dimensions is not supported.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-f49c-87jh-g47q
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35974: Segfault in 'QuantizeDownAndShrinkRange'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-vgvh-2pf4-jr2x
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 update 'curl' to v7.83.1 to handle CVE-2022-27781.
|
|
tensorflow
|
2.5.3
|
<2.11.1 ,
>=2.12.0rc0,<2.12.0
|
show Tensorflow 2.11.1 and 2.12.0 include a fix for CVE-2023-25668: Attackers using Tensorflow prior to 2.12.0 or 2.11.1 can access heap memory which is not in the control of user, leading to a crash or remote code execution.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-gw97-ff7c-9v96
|
|
tensorflow
|
2.5.3
|
<2.12.1 ,
>=2.13.0rc0,<2.13.0
|
show Affected versions of Tensorflow are vulnerable to Integer Overflow. array_ops.upper_bound' causes a segfault when not given a rank 2 tensor. The flaw was fixed in May 30, 2023, but the CVE was published in July 30, 2024. It was noticed unpublished by the Safety CLI Cyber Security team.
|
|
tensorflow
|
2.5.3
|
<2.8.4 ,
>=2.9.0rc0,<2.9.3 ,
>=2.10.0rc0,<2.10.1
|
show Tensorflow 2.8.4, 2.9.3 and 2.10.1 include a fix for CVE-2022-41884: If a numpy array is created with a shape such that one element is zero and the others sum to a large number, an error will be raised.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-jq6x-99hj-q636
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35952: 'CHECK' failures in 'UnbatchGradOp'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-h5vq-gw2c-pq47
|
|
tensorflow
|
2.5.3
|
<2.8.4 ,
>=2.9.0rc0,<2.9.3 ,
>=2.10.0rc0,<2.10.1
|
show Tensorflow 2.8.4, 2.9.3 and 2.10.1 include a fix for CVE-2022-41891: If 'tf.raw_ops.TensorListConcat' is given 'element_shape=[]', it results segmentation fault which can be used to trigger a denial of service attack.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-66vq-54fq-6jvv
|
|
tensorflow
|
2.5.3
|
<2.11.1 ,
>=2.12.0rc0,<2.12.0
|
show Tensorflow 2.11.1 and 2.12.0 include a fix for CVE-2023-25659: Prior to versions 2.12.0 and 2.11.1, if the parameter 'indices' for 'DynamicStitch' does not match the shape of the parameter 'data', it can trigger an stack OOB read.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-93vr-9q9m-pj8p
|
|
tensorflow
|
2.5.3
|
<2.8.4 ,
>=2.9.0rc0,<2.9.3 ,
>=2.10.0rc0,<2.10.1
|
show Tensorflow 2.8.4, 2.9.3 and 2.10.1 include a fix for CVE-2022-41889: If a list of quantized tensors is assigned to an attribute, the pywrap code fails to parse the tensor and returns a 'nullptr', which is not caught. An example can be seen in 'tf.compat.v1.extract_volume_patches' by passing in quantized tensors as input 'ksizes'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-xxcj-rhqg-m46g
|
|
tensorflow
|
2.5.3
|
<2.8.4 ,
>=2.9.0rc0,<2.9.3 ,
>=2.10.0rc0,<2.10.1
|
show Tensorflow 2.8.4, 2.9.3 and 2.10.1 include a fix for CVE-2022-41896: If 'ThreadUnsafeUnigramCandidateSampler' is given input 'filterbank_channel_count' greater than the allowed max size, TensorFlow will crash.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-rmg2-f698-wq35
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-36001: 'CHECK' fail in 'DrawBoundingBoxes'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-jqm7-m5q7-3hm5
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35986: Segfault in 'RaggedBincount'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-wr9v-g9vf-c74v
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 include a fix for CVE-2022-29201: Missing validation which results in undefined behavior in 'QuantizedConv2D'.
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-36002: 'CHECK' fail in 'Unbatch'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-mh3m-62v7-68xg
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35984: 'CHECK' fail in 'ParameterizedTruncatedNormal'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-p2xf-8hgm-hpw5
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 include a fix for CVE-2022-29206: Missing validation which results in undefined behavior in 'SparseTensorDenseAdd'.
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35981: 'CHECK' fail in 'FractionalMaxPoolGrad'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-vxv8-r8q2-63xw
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 update 'curl' to v7.83.1 to handle CVE-2022-27774.
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 update 'curl' to v7.83.1 to handle CVE-2022-27779.
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 include a fix for CVE-2022-29207: Issues arising from undefined behavior stemming from users supplying invalid resource handles.
|
|
tensorflow
|
2.5.3
|
<2.8.4 ,
>=2.9.0rc0,<2.9.3 ,
>=2.10.0rc0,<2.10.1 ,
>=2.11.0rc0,<2.11.0
|
show TensorFlow 2.8.4, 2.9.3, 2.10.1 and 2.11.0 include a fix for CVE-2022-35991: 'CHECK' fail in 'TensorListScatter' and 'TensorListScatterV2'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-vm7x-4qhj-rrcq
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-xf83-q765-xm6m
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35966: Segfault in 'QuantizedAvgPool'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-4w68-4x85-mjj9
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 include a fix for CVE-2022-29208: Segfault and OOB write due to incomplete validation in 'EditDistance'.
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35970: Segfault in 'QuantizedInstanceNorm'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-g35r-369w-3fqp
|
|
tensorflow
|
2.5.3
|
<2.11.1 ,
>=2.12.0rc0,<2.12.0
|
show Tensorflow 2.11.1 and 2.12.0 include a fix for CVE-2023-25666: Prior to versions 2.12.0 and 2.11.1, there is a floating point exception in AudioSpectrogram. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-f637-vh3r-vfh2
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Tensorflow versions 2.6.4, 2.7.2, 2.8.1 and 2.9.0 update 'curl' to v7.83.1 to handle CVE-2022-22576.
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35989: 'CHECK' fail in 'MaxPool'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-j43h-pgmg-5hjq
|
|
tensorflow
|
2.5.3
|
<2.8.4 ,
>=2.9.0rc0,<2.9.3 ,
>=2.10.0rc0,<2.10.1
|
show Tensorflow 2.8.4, 2.9.3 and 2.10.1 include a fix for CVE-2022-41888: When running on GPU, 'tf.image.generate_bounding_box_proposals' receives a 'scores' input that must be of rank 4 but is not checked.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-6x99-gv2v-q76v
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35967: Segfault in 'QuantizedAdd'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-v6h3-348g-6h5x
|
|
tensorflow
|
2.5.3
|
<2.11.1 ,
>=2.12.0rc0,<2.12.0
|
show Tensorflow 2.11.1 and 2.12.0 include a fix for CVE-2023-25661: In versions prior to 2.11.1 a malicious invalid input crashes a tensorflow model (Check Failed) and can be used to trigger a denial of service attack. A proof of concept can be constructed with the 'Convolution3DTranspose' function. This Convolution3DTranspose layer is a very common API in modern neural networks. The ML models containing such vulnerable components could be deployed in ML applications or as cloud services. This failure could be potentially used to trigger a denial of service attack on ML cloud services. An attacker must have privilege to provide input to a 'Convolution3DTranspose' call.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-fxgc-95xx-grvq
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35994: 'CHECK' fail in 'CollectiveGather'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-fhfc-2q7x-929f
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-36015: Integer overflow in math ops.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-rh87-q4vg-m45j
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35969: 'CHECK' fail in 'Conv2DBackpropInput'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-q2c3-jpmc-gfjx
|
|
tensorflow
|
2.5.3
|
<2.11.1 ,
>=2.12.0rc0,<2.12.0
|
show Tensorflow 2.11.1 and 2.12.0 include a fix for CVE-2023-25669: Prior to versions 2.12.0 and 2.11.1, if the stride and window size are not positive for 'tf.raw_ops.AvgPoolGrad', it can give a floating point exception.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-rcf8-g8jv-vg6p
|
|
tensorflow
|
2.5.3
|
<2.8.4 ,
>=2.9.0rc0,<2.9.3 ,
>=2.10.0rc0,<2.10.1
|
show Tensorflow 2.8.4, 2.9.3 and 2.10.1 include a fix for CVE-2022-41893: If 'tf.raw_ops.TensorListResize' is given a nonscalar value for input 'size', it results 'CHECK' fail which can be used to trigger a denial of service attack.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-67pf-62xr-q35m
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-36016: 'CHECK'-fail in 'tensorflow::full_type::SubstituteFromAttrs'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-g468-qj8g-vcjc
|
|
tensorflow
|
2.5.3
|
<2.11.1 ,
>=2.12.0rc0,<2.12.0
|
show Tensorflow 2.11.1 and 2.12.0 include a fix for CVE-2023-25662: Versions prior to 2.12.0 and 2.11.1 are vulnerable to integer overflow in EditDistance.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-7jvm-xxmr-v5cw
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35987: 'CHECK' fail in 'DenseBincount'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-w62h-8xjm-fv49
|
|
tensorflow
|
2.5.3
|
<2.9.3 ,
>=2.10.0rc0,<2.10.1
|
show Tensorflow 2.9.3 and 2.10.1 include a fix for CVE-2022-41887: 'tf.keras.losses.poisson' receives a 'y_pred' and 'y_true' that are passed through 'functor::mul' in 'BinaryOp'. If the resulting dimensions overflow an 'int32', TensorFlow will crash due to a size mismatch during broadcast assignment.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-8fvv-46hw-vpg3
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-36000: 'CHECK' fail in 'Eig'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-fqxc-pvf8-2w9v
|
|
tensorflow
|
2.5.3
|
<2.8.4 ,
>=2.9.0rc0,<2.9.3 ,
>=2.10.0rc0,<2.10.1
|
show Tensorflow 2.8.4, 2.9.3 and 2.10.1 include a fix for CVE-2022-41909: An input 'encoded' that is not a valid 'CompositeTensorVariant' tensor will trigger a segfault in 'tf.raw_ops.CompositeTensorVariantToComponents'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-rjx6-v474-2ch9
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35996: Floating point exception in 'Conv2D'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-q5jv-m6qw-5g37
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-35960: 'CHECK' failure in 'TensorListReserve' via missing validation.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-v5xg-3q2c-c2r4
|
|
tensorflow
|
2.5.3
|
<2.11.1 ,
>=2.12.0rc0,<2.12.0
|
show Tensorflow 2.11.1 and 2.12.0 include a fix for CVE-2023-25673: Versions prior to 2.12.0 and 2.11.1 have a Floating Point Exception in TensorListSplit with XLA. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.
|
|
tensorflow
|
2.5.3
|
<2.7.4 ,
>=2.8.0rc0,<2.8.3 ,
>=2.9.0rc0,<2.9.2
|
show TensorFlow 2.7.4, 2.8.3 and 2.9.2 include a fix for CVE-2022-36013: Null-dereference in 'mlir::tfg::GraphDefImporter::ConvertNodeDef'.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-828c-5j5q-vrjq
|
|
tensorflow
|
2.5.3
|
>=0,<2.8.4 ,
>=2.9.0,<2.9.3 ,
>=2.10.0,<2.10.1
|
show Affected versions of TensorFlow are susceptible to a Denial of Service (DoS) attack caused by an issue similar to CVE-2022-35991, occurring in TensorListScatter and TensorListScatterV2 when non-scalar inputs are used.
|
|
tensorflow
|
2.5.3
|
<2.6.4 ,
>=2.7.0rc0,<2.7.2 ,
>=2.8.0rc0,<2.8.1 ,
>=2.9.0rc0,<2.9.0
|
show Affected versions of Tensorflow are vulnerable to Denial of Service in the implementation of depthwise ops via CHECK-failure (assertion failure) caused by overflowing the number of elements in a tensor. This is another instance of TFSA-2021-198 (CVE-2021-41197).
|
|
tensorflow
|
2.5.3
|
<2.8.4 ,
>=2.9.0rc0,<2.9.3 ,
>=2.10.0rc0,<2.10.1
|
show Tensorflow 2.8.4, 2.9.3 and 2.10.1 include a fix for CVE-2022-41902: The function MakeGrapplerFunctionItem takes arguments that determine the sizes of inputs and outputs. If the inputs given are greater than or equal to the sizes of the outputs, an out-of-bounds memory read or a crash is triggered.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-cg88-rpvp-cjv5
|