Логотип exploitDog
bind:CVE-2022-41911
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-41911

Количество 4

Количество 4

nvd логотип

CVE-2022-41911

около 3 лет назад

TensorFlow is an open source platform for machine learning. When printing a tensor, we get it's data as a `const char*` array (since that's the underlying storage) and then we typecast it to the element type. However, conversions from `char` to `bool` are undefined if the `char` is not `0` or `1`, so sanitizers/fuzzers will crash. The issue has been patched in GitHub commit `1be74370327`. The fix will be included in TensorFlow 2.11.0. We will also cherrypick this commit on TensorFlow 2.10.1, TensorFlow 2.9.3, and TensorFlow 2.8.4, as these are also affected and still in supported range.

CVSS3: 4.8
EPSS: Низкий
msrc логотип

CVE-2022-41911

около 3 лет назад

Invalid char to bool conversion when printing a tensor in Tensorflow

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-41911

около 3 лет назад

TensorFlow is an open source platform for machine learning. When print ...

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-pf36-r9c6-h97j

около 3 лет назад

Invalid char to bool conversion when printing a tensor

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-41911

TensorFlow is an open source platform for machine learning. When printing a tensor, we get it's data as a `const char*` array (since that's the underlying storage) and then we typecast it to the element type. However, conversions from `char` to `bool` are undefined if the `char` is not `0` or `1`, so sanitizers/fuzzers will crash. The issue has been patched in GitHub commit `1be74370327`. The fix will be included in TensorFlow 2.11.0. We will also cherrypick this commit on TensorFlow 2.10.1, TensorFlow 2.9.3, and TensorFlow 2.8.4, as these are also affected and still in supported range.

CVSS3: 4.8
0%
Низкий
около 3 лет назад
msrc логотип
CVE-2022-41911

Invalid char to bool conversion when printing a tensor in Tensorflow

CVSS3: 7.5
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-41911

TensorFlow is an open source platform for machine learning. When print ...

CVSS3: 4.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-pf36-r9c6-h97j

Invalid char to bool conversion when printing a tensor

CVSS3: 4.8
0%
Низкий
около 3 лет назад

Уязвимостей на страницу