NULL pointer dereference in TensorFlow - CVE-2022-29205
Published: May 17, 2022 / Updated: May 3, 2026
TensorFlow
TensorFlow
Description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in ParseDimensionValue when processing tf.compat.v1 ops with quantized types that lack kernel support. A local user can call a vulnerable operation with a crafted quantized type input to cause a denial of service.