CVE-2022-23558 is a high-severity integer overflow vulnerability affecting Google TensorFlow, specifically within the TFLite model's TfLiteIntArrayCreate function. An attacker can craft malicious TFLite model inputs to cause an integer overflow in the size calculation, leading to potential denial of service, information disclosure, or arbitrary code execution. With a CVSS score of 8.8, this vulnerability is easily exploitable over the network with low privileges and no user interaction. While no public exploits or active exploitation have been observed, and community discussion is minimal, patches are available in TensorFlow 2.8.0 and backported to 2.7.1, 2.6.3, and 2.5.3.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.5.2CPE matchmatch criteria | cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:* | ||
>= 2.6.0, <= 2.6.2CPE matchmatch criteria | cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:* | ||
2.7.0CPE matchmatch criteria | cpe:2.3:a:google:tensorflow:2.7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.