Aller au contenu

Fiche vulnérabilité

CVE-2022-23562 : faille élevée tensorflow tensorflow (CVSS 7.6)

Description

Tensorflow is an Open Source Machine Learning Framework. The implementation of `Range` suffers from integer overflows. These can trigger undefined behavior or, in some scenarios, extremely large allocations. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow 2.6.3, and TensorFlow 2.5.3, as these are also affected and still in supported range.

En bref

Sévérité
Élevée (CVSS 7.6)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Exploitation active
Non signalée par la CISA
Publication
4 févr. 2022
Dernière mise à jour
23 avr. 2025

Produits concernés

  • tensorflow tensorflow

Références

Rechercher une autre vulnérabilité dans la base CVE