CVE-2022-41886
TensorFlow is an open source platform for machine learning. When `tf.raw_ops.ImageProjectiveTransformV2` is given a large output shape, it overflows. We have patched the issue in GitHub commit 8faa6ea692985dbe6ce10e1a3168e0bd60a723ba. The fix will be included in TensorFlow 2.11. We will also cherrypick this commit on TensorFlow 2.10.1, 2.9.3, and TensorFlow 2.8.4, as these are also affected and still in supported range.
- Affected products
- Tensorflow
- Google Tensorflow
- < 2.8.4, 2.9.3, 2.10.0
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 0.4% (35th percentile)
- Weakness
- CWE-131
- NVD status
- Modified
- Published
- 2022-11-18
CVE-2022-41886 at NVD
No indexed exploits for CVE-2022-41886 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2022-41886 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.