Tensorflow is an Open Source Machine Learning Framework. The implementation of SparseCountSparseOutput is vulnerable to a heap overflow. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow 2.6.3, and TensorFlow 2.5.3, as these are also affected and still in supported range.
[
{
"signature_version": "v1",
"target": {
"file": "tensorflow/core/kernels/count_ops.cc"
},
"source": "https://github.com/tensorflow/tensorflow/commit/adbbabdb0d3abb3cdeac69e38a96de1d678b24b3",
"digest": {
"line_hashes": [
"158263268095599937450691628573072786630",
"160541767295110924866832789993868436395",
"216390658124029088732242069207141239049",
"333425490335565698490840316472876122211",
"334559556666108742657391365132510129112",
"61983250020719810322228114056382812888",
"7874507959324440005089441570945882077",
"301236683294651696000716452026061077059",
"215819206851622813427307711563146517518",
"258269043845378943323439520251720571782",
"25098771025719159148802304671429039007"
],
"threshold": 0.9
},
"deprecated": false,
"id": "CVE-2022-21740-a87022ed",
"signature_type": "Line"
},
{
"signature_version": "v1",
"target": {
"file": "tensorflow/core/kernels/count_ops.cc"
},
"source": "https://github.com/tensorflow/tensorflow/commit/2b7100d6cdff36aa21010a82269bc05a6d1cc74a",
"digest": {
"line_hashes": [
"122268366615870984061731212483338613608",
"331197975007086142495442295116876276889",
"274333202759242867661362820132762296942",
"24540839225558138880736723824630938445",
"54986795225819630183321432706554493921",
"111387036045776398925780042773652253108",
"236414246192172195641386631347115688475",
"331528481227994275889744815991125017247",
"270153746900716505495932950264790376392",
"12092929553094343785797268482198443203",
"7874507959324440005089441570945882077",
"70292989773184290943277274873153948233",
"37784336467189883900985648367146805012",
"78255415891508767832834393378684214991",
"119301024285150303581569650604645531891",
"242432251648936141967772996842232720327",
"80743426556312547582870807565152435026",
"305542167729994706683797306584931349203",
"113972689815413783749537851093374806771",
"15095870996015274044393628556655552557",
"88406783310725338448377167891769338516",
"176815940850939357411414247040828562788",
"282861960725116743484462341347643923394",
"245670380746282353972333627797044514944",
"145240645846633392420339396997140337622",
"142502283888192935441185518778031548263",
"286146451268294583632579489631235618492",
"242813962013336255070449395816118815813",
"323975600079809876117292672000661218444",
"148200533338745609053035860708214667501",
"280770808928017248684546375780452873765",
"167428460600871771954203503171272625576",
"51280031490941488587456689041229912459",
"61473214249927899287073148589492835079",
"211611697522199923154704004340082255571",
"314009107591415659434262482843296394448",
"3878503606720120236402875860279767962"
],
"threshold": 0.9
},
"deprecated": false,
"id": "CVE-2022-21740-f56d89b8",
"signature_type": "Line"
}
]