CVE-2022-41909 describes a denial-of-service vulnerability in TensorFlow, an open-source machine learning platform. Specifically, an invalid input to the tf.raw_ops.CompositeTensorVariantToComponents function can trigger a segmentation fault, leading to application crashes. This vulnerability affects TensorFlow versions 2.8.x, 2.9.x, and 2.10.x. The vulnerability carries a CVSS score of 7.5 (High), indicating a significant risk. It is a network-exploitable vulnerability with low attack complexity, requiring no user interaction or privileges, and its primary impact is a complete loss of availability (A:H). Currently, there is no evidence of active exploitation, nor is there publicly available exploit code in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are also minimal, suggesting low public awareness at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.8.4CPE matchmatch criteria | cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:* | ||
>= 2.9.0, < 2.9.3CPE matchmatch criteria | cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:* | ||
2.10.0CPE matchmatch criteria | cpe:2.3:a:google:tensorflow:2.10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.