Out of bounds read in Tensorflow
High8.1CVE-2022-23592 · Published Feb 9, 2022 · updated Jul 13, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| tensorflow PyPI | >= 2.8.0-rc0, < 2.8.0 | 2.8.0 |
Details and references
### Impact TensorFlow's [type inference](https://github.com/tensorflow/tensorflow/blob/274df9b02330b790aa8de1cee164b70f72b9b244/tensorflow/core/graph/graph.cc#L223-L229) can cause a heap OOB read as the bounds checking is done in a `DCHECK` (which is a no-op during production): ```cc if (node_t.type_id() != TFT_UNSET) { int ix = input_idx[i]; DCHECK(ix < node_t.args_size()) << "input " << i << " should have an output " << ix << " but instead only has " << node_t.args_size() << " outputs: " << node_t.DebugString(); input_types.emplace_back(node_t.args(ix)); // ... } ``` An attacker can control `input_idx` such that `ix` would be larger than the number of values in `node_t.args`. ### Patches We have patched the issue in GitHub commit [c99d98cd189839dcf51aee94e7437b54b31f8abd](https://github.com/tensorflow/tensorflow/commit/c99d98cd189839dcf51aee94e7437b54b31f8abd). The fix will be included in TensorFlow 2.8.0. This is the only affected version. ### For more information Please consult [our security guide](https://github.com/tensorflow/tensorflow/blob/master/SECURITY.md) for more information regarding the security model and how to contact us with issues and questions.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-125
- Also known as
- BIT-tensorflow-2022-23592, CVE-2022-23592, PYSEC-2022-101, PYSEC-2022-156, PYSEC-2026-3249
- github.com/tensorflow/tensorflow/security/advisories/GHSA-vq36-27g6-p492
- nvd.nist.gov/vuln/detail/CVE-2022-23592
- github.com/tensorflow/tensorflow/commit/c99d98cd189839dcf51aee94e7437b54b31f8abd
- github.com/pypa/advisory-database/tree/main/vulns/tensorflow-cpu/PYSEC-2022-101.yaml
- github.com/pypa/advisory-database/tree/main/vulns/tensorflow-gpu/PYSEC-2022-156.yaml
- github.com/tensorflow/tensorflow
- github.com/tensorflow/tensorflow/blob/274df9b02330b790aa8de1cee164b70f72b9b244/tensorflow/core/graph/graph.cc#L223-L229
More TensorFlow advisories
All TensorFlow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 92022 | Out of bounds read in Tensorflow CVE-2022-21726High8.1fixed in 2.5.3, 2.6.3, 2.7.1 | High8.1 | 2.5.3, 2.6.3, 2.7.1 |
| Feb 92022 | Integer overflow in Tensorflow CVE-2022-21727High7.6fixed in 2.5.3, 2.6.3, 2.7.1 | High7.6 | 2.5.3, 2.6.3, 2.7.1 |
| Feb 92022 | Out of bounds read in Tensorflow CVE-2022-21728High8.1fixed in 2.5.3, 2.6.3, 2.7.1 | High8.1 | 2.5.3, 2.6.3, 2.7.1 |
| Feb 92022 | Out of bounds read in Tensorflow CVE-2022-21730High8.1fixed in 2.5.3, 2.6.3, 2.7.1 | High8.1 | 2.5.3, 2.6.3, 2.7.1 |
| Feb 92022 | Out of bounds read and write in Tensorflow CVE-2022-23574High8.8fixed in 2.5.3, 2.6.3, 2.7.1 | High8.8 | 2.5.3, 2.6.3, 2.7.1 |
| Feb 92022 | Memory leak in decoding PNG images CVE-2022-23585Medium4.3fixed in 2.5.3, 2.6.3, 2.7.1 | Medium4.3 | 2.5.3, 2.6.3, 2.7.1 |