NULL pointer dereference in TensorFlow - CVE-2022-23589
Published: February 2, 2022 / Updated: May 3, 2026
TensorFlow
TensorFlow
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in Grappler's IsConstant constant folding logic and IsIdentityConsumingSwitch when processing a maliciously altered SavedModel file. A remote attacker can supply a specially crafted SavedModel file to cause a denial of service.