Input validation error in TensorFlow - CVE-2022-35988
Published: September 15, 2022 / Updated: May 3, 2026
TensorFlow
TensorFlow
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in tf.linalg.matrix_rank when processing an empty input tensor on the GPU kernel. A remote attacker can supply a crafted empty input to cause a denial of service.
The issue is triggered when the operation receives an empty input a.