CVE-2022-29205
Segfault due to missing support for quantized types in TensorFlow
Description
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, there is a potential for segfault / denial of service in TensorFlow by calling `tf.compat.v1.*` ops which don't yet have support for quantized types, which was added after migration to TensorFlow 2.x. In these scenarios, since the kernel is missing, a `nullptr` value is passed to `ParseDimensionValue` for the `py_value` argument. Then, this is dereferenced, resulting in segfault. Versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4 contain a patch for this issue.
How to fix CVE-2022-29205
To remediate CVE-2022-29205, upgrade the affected package to a fixed version below.
- —upgrade to 2.6.4 or later
- —upgrade to 2.6.4 or later
- —upgrade to 2.6.4 or later
- —upgrade to 2.6.4 or later
Is CVE-2022-29205 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (4)
- from 0, < 2.6.4, >= 2.7.0, < 2.7.2, >= 2.8.0, < 2.8.1
- from 0, < 2.6.4
- from 0, < 2.6.4
- from 0, < 2.6.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |