Vulnerability Description
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, certain TFLite models that were created using TFLite model converter would crash when loaded in the TFLite interpreter. The culprit is that during quantization the scale of values could be greater than 1 but code was always assuming sub-unit scaling. Thus, since code was calling `QuantizeMultiplierSmallerThanOneExp`, the `TFLITE_CHECK_LT` assertion would trigger and abort the process. Versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4 contain a patch for this issue.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tensorflow | < 2.6.4 |
Related Weaknesses (CWE)
References
- https://github.com/tensorflow/tensorflow/blob/f3b9bf4c3c0597563b289c0512e98d4ce8Third Party Advisory
- https://github.com/tensorflow/tensorflow/commit/a989426ee1346693cc015792f11d715fPatchThird Party Advisory
- https://github.com/tensorflow/tensorflow/issues/43661ExploitIssue TrackingThird Party Advisory
- https://github.com/tensorflow/tensorflow/releases/tag/v2.6.4Release NotesThird Party Advisory
- https://github.com/tensorflow/tensorflow/releases/tag/v2.7.2Release NotesThird Party Advisory
- https://github.com/tensorflow/tensorflow/releases/tag/v2.8.1Release NotesThird Party Advisory
- https://github.com/tensorflow/tensorflow/releases/tag/v2.9.0Release NotesThird Party Advisory
- https://github.com/tensorflow/tensorflow/security/advisories/GHSA-8wwm-6264-x792ExploitPatchThird Party Advisory
- https://github.com/tensorflow/tensorflow/blob/f3b9bf4c3c0597563b289c0512e98d4ce8Third Party Advisory
- https://github.com/tensorflow/tensorflow/commit/a989426ee1346693cc015792f11d715fPatchThird Party Advisory
- https://github.com/tensorflow/tensorflow/issues/43661ExploitIssue TrackingThird Party Advisory
- https://github.com/tensorflow/tensorflow/releases/tag/v2.6.4Release NotesThird Party Advisory
- https://github.com/tensorflow/tensorflow/releases/tag/v2.7.2Release NotesThird Party Advisory
- https://github.com/tensorflow/tensorflow/releases/tag/v2.8.1Release NotesThird Party Advisory
- https://github.com/tensorflow/tensorflow/releases/tag/v2.9.0Release NotesThird Party Advisory
FAQ
What is CVE-2022-29212?
CVE-2022-29212 is a vulnerability with a CVSS score of 5.5 (MEDIUM). TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, certain TFLite models that were created using TFLite model converter would crash when load...
How severe is CVE-2022-29212?
CVE-2022-29212 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-29212?
Check the references section above for vendor advisories and patch information. Affected products include: Google Tensorflow.