Input validation error in TensorFlow - CVE-2022-35999
Published: September 15, 2022 / Updated: May 3, 2026
TensorFlow
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in Conv2DBackpropInput when processing empty out_backprop inputs. A remote attacker can supply a crafted input tensor to cause a denial of service.
The issue affects the CPU and GPU kernels.