Описание
CHECK fail via inputs in SdcaOptimizer
Impact
Inputs dense_features or example_state_data not of rank 2 will trigger a CHECK fail in SdcaOptimizer.
Patches
We have patched the issue in GitHub commit 80ff197d03db2a70c6a111f97dcdacad1b0babfa.
The fix will be included in TensorFlow 2.11. We will also cherrypick this commit on TensorFlow 2.10.1, 2.9.3, and TensorFlow 2.8.4, as these are also affected and still in supported range.
For more information
Please consult our security guide for more information regarding the security model and how to contact us with issues and questions.
Attribution
This vulnerability has been reported by Zizhuang Deng of IIE, UCAS
Ссылки
- https://github.com/tensorflow/tensorflow/security/advisories/GHSA-27rc-728f-x5w2
- https://nvd.nist.gov/vuln/detail/CVE-2022-41899
- https://github.com/tensorflow/tensorflow/commit/80ff197d03db2a70c6a111f97dcdacad1b0babfa
- https://github.com/tensorflow/tensorflow/blob/master/tensorflow/core/kernels/sdca_internal.cc
Пакеты
tensorflow
< 2.8.4
2.8.4
tensorflow
>= 2.9.0, < 2.9.3
2.9.3
tensorflow
>= 2.10.0, < 2.10.1
2.10.1
tensorflow-cpu
< 2.8.4
2.8.4
tensorflow-gpu
< 2.8.4
2.8.4
tensorflow-cpu
>= 2.9.0, < 2.9.3
2.9.3
tensorflow-gpu
>= 2.9.0, < 2.9.3
2.9.3
tensorflow-cpu
>= 2.10.0, < 2.10.1
2.10.1
tensorflow-gpu
>= 2.10.0, < 2.10.1
2.10.1
Связанные уязвимости
TensorFlow is an open source platform for machine learning. Inputs `dense_features` or `example_state_data` not of rank 2 will trigger a `CHECK` fail in `SdcaOptimizer`. We have patched the issue in GitHub commit 80ff197d03db2a70c6a111f97dcdacad1b0babfa. The fix will be included in TensorFlow 2.11. We will also cherrypick this commit on TensorFlow 2.10.1, 2.9.3, and TensorFlow 2.8.4, as these are also affected and still in supported range.
`CHECK` fail via inputs in `SdcaOptimizer` in Tensorflow
TensorFlow is an open source platform for machine learning. Inputs `de ...