Sploitus

CVE-2022-29208

No indexed exploits for CVE-2022-29208 yet

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.EditDistance` has incomplete validation. Users can pass negative values to cause a segmentation fault based denial of service. In multiple places throughout the code, one may compute an index for a write operation. However, the existing validation only checks against the upper bound of the array. Hence, it is possible to write before the array by massaging the input to generate negative values for `loc`. Versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4 contain a patch for this issue.

Affected products
Tensorflow
Google Tensorflow
< 2.6.4, 2.7.2, 2.7.0, 2.8.0, 2.9.0
Fix
Available
CVSS 3.1
7.1 HIGH
EPSS
0.4% (31th percentile)
Weakness
CWE-787
NVD status
Modified
Published
2022-05-20
CVE-2022-29208 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2022-29208 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2022-29208 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.