NULL pointer dereference in TensorFlow - CVE-2022-35965
Published: September 15, 2022 / Updated: May 3, 2026
TensorFlow
TensorFlow
Description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a nullptr dereference in the LowerBound and UpperBound operations when processing an empty sorted_inputs input. A local user can supply crafted input tensors to trigger a segmentation fault and cause a denial of service.