Input validation error in TensorFlow - CVE-2022-35998
Published: September 15, 2022 / Updated: May 3, 2026
TensorFlow
TensorFlow
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in EmptyTensorList when processing an element_shape input with more than one dimension. A remote attacker can supply a specially crafted element_shape value to cause a denial of service.