CVE-2022-23588
`CHECK`-fails due to attempting to build a reference tensor in Tensorflow
6.5
MEDIUM
CVSS 3.1
EPSS 0.86%
描述
Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that Grappler optimizer would attempt to build a tensor using a reference `dtype`. This would result in a crash due to a `CHECK`-fail in the `Tensor` constructor as reference types are not allowed. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow 2.6.3, and TensorFlow 2.5.3, as these are also affected and still in supported range.
如何修補 CVE-2022-23588
要修補 CVE-2022-23588,請將受影響套件升級到下列已修補版本。
- —升級至 2.5.3 或更新版本
- —升級至 2.5.3 或更新版本
- —升級至 2.5.3 或更新版本
- —升級至 2.5.3 或更新版本
- —升級至 6b5adc0877de832b2a7c189532dbbbc64622eeb6 或更新版本
- —升級至 2.5.3 或更新版本
- —升級至 6b5adc0877de832b2a7c189532dbbbc64622eeb6 或更新版本
CVE-2022-23588 正在被利用嗎?
低 — EPSS 為 0.9%,目前沒有觀察到大規模利用活動。
受影響套件(7)
- from 0, < 2.5.3, >= 2.6.0, < 2.6.3, >= 2.7.0, < 2.7.1
- from 0, < 2.5.3
- from 0, < 2.5.3, >= 2.6.0, < 2.6.3, >= 2.7.0, < 2.7.1
- from 0, < 2.5.3
- from 0, < 6b5adc0877de832b2a7c189532dbbbc64622eeb6 | from 0, < 2.5.3, >= 2.6.0, < 2.6.3
- from 0, < 2.5.3
- from 0, < 6b5adc0877de832b2a7c189532dbbbc64622eeb6 | from 0, < 2.5.3, >= 2.6.0, < 2.6.3
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |