Количество 3
Количество 3
CVE-2022-29198
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.SparseTensorToCSRSparseMatrix` does not fully validate the input arguments. This results in a `CHECK`-failure which can be used to trigger a denial of service attack. The code assumes `dense_shape` is a vector and `indices` is a matrix (as part of requirements for sparse tensors) but there is no validation for this. Versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4 contain a patch for this issue.
CVE-2022-29198
TensorFlow is an open source platform for machine learning. Prior to v ...
GHSA-mg66-qvc5-rm93
Missing validation causes denial of service via `SparseTensorToCSRSparseMatrix`
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-29198 TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.SparseTensorToCSRSparseMatrix` does not fully validate the input arguments. This results in a `CHECK`-failure which can be used to trigger a denial of service attack. The code assumes `dense_shape` is a vector and `indices` is a matrix (as part of requirements for sparse tensors) but there is no validation for this. Versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4 contain a patch for this issue. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
CVE-2022-29198 TensorFlow is an open source platform for machine learning. Prior to v ... | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-mg66-qvc5-rm93 Missing validation causes denial of service via `SparseTensorToCSRSparseMatrix` | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу