Input validation error in TensorFlow - CVE-2022-35966
Published: September 15, 2022 / Updated: May 3, 2026
TensorFlow
TensorFlow
Description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in QuantizedAvgPool when processing min_input or max_input tensors of a nonzero rank. A local user can supply crafted tensors to trigger a segmentation fault and cause a denial of service.