Input validation error in TensorFlow - CVE-2022-36016
Published: September 15, 2022 / Updated: May 2, 2026
TensorFlow
TensorFlow
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in tensorflow::full_type::SubstituteFromAttrs when processing a FullTypeDef input. A remote attacker can supply a crafted FullTypeDef with an invalid number of arguments to cause a denial of service.