Input validation error in TensorFlow - CVE-2022-35987
Published: September 15, 2022 / Updated: May 3, 2026
TensorFlow
TensorFlow
Description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in the DenseBincount operation when processing input tensors with a weights tensor whose shape differs from the input tensor and is not length-0. A local user can supply crafted tensor inputs to trigger a check failure and cause a denial of service.