PT-2022-16106 · Google · Tensorflow

·

CVE-2022-23589

·

Published

2022-02-04

·

Updated

2026-07-09

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions TensorFlow versions prior to 2.8.0 TensorFlow versions 2.7.1 and earlier TensorFlow versions 2.6.3 and earlier TensorFlow versions 2.5.3 and earlier
Description The Grappler component of TensorFlow can trigger a null pointer dereference under certain scenarios. This issue occurs in two places due to the malicious alteration of a SavedModel file. The first instance happens during constant folding when the GraphDef lacks the required nodes for a binary operation, resulting in a null mul *child and incorrect dereference. A similar issue arises during IsIdentityConsumingSwitch.
Recommendations For versions prior to 2.8.0, update to TensorFlow 2.8.0 or later. For versions 2.7.1 and earlier, update to TensorFlow 2.7.1 or later. For versions 2.6.3 and earlier, update to TensorFlow 2.6.3 or later. For versions 2.5.3 and earlier, update to TensorFlow 2.5.3 or later.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-TENSORFLOW-2022-23589
CVE-2022-23589
GHSA-9PX9-73FG-3FQP
OPENSUSE-SU-2024:12116-1
PYSEC-2022-153
PYSEC-2022-98
PYSEC-2026-3154

Affected Products

Tensorflow