CVE-2022-23581

MEDIUM

Google Tensorflow < 2.5.2 - Reachable Assertion

Title source: rule
STIX 2.1

Description

Tensorflow is an Open Source Machine Learning Framework. The Grappler optimizer in TensorFlow can be used to cause a denial of service by altering a `SavedModel` such that `IsSimplifiableReshape` would trigger `CHECK` failures. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow 2.6.3, and TensorFlow 2.5.3, as these are also affected and still in supported range.

Scores

CVSS v3 6.5
EPSS 0.0048
EPSS Percentile 65.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-617
Status published
Products (5)
google/tensorflow 2.7.0
google/tensorflow < 2.5.2
pypi/tensorflow 0 - 2.5.3PyPI
pypi/tensorflow-cpu 0 - 2.5.3PyPI
pypi/tensorflow-gpu 0 - 2.5.3PyPI
Published Feb 04, 2022
Tracked Since Feb 18, 2026