Input validation error in TensorFlow - CVE-2022-21725
Published: February 2, 2022 / Updated: May 3, 2026
TensorFlow
TensorFlow
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the convolution cost estimator when processing convolution operators with a zero stride value. A remote attacker can supply crafted input that sets the stride to zero to cause a denial of service.