Integer overflow in TensorFlow - CVE-2022-36015
Published: September 15, 2022 / Updated: May 2, 2026
TensorFlow
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in RangeSize in tensorflow/core/ops/math_ops.cc when processing crafted range values that do not fit into an int64_t. A remote attacker can supply crafted input values to trigger a crash to cause a denial of service.