Integer overflow in TensorFlow - CVE-2022-23575
Published: February 2, 2022 / Updated: May 3, 2026
TensorFlow
Detailed vulnerability description
The vulnerability allows a remote attacker to cause an integer overflow.
The vulnerability exists due to integer overflow in OpLevelCostEstimator::CalculateTensorSize when calculating the size of a tensor with a large enough number of elements. A remote attacker can create an operation involving a tensor with a sufficiently large element count to cause an integer overflow.