#VU86672 Always-Incorrect Control Flow Implementation in TensorFlow - CVE-2022-41884
Published: February 21, 2024
TensorFlow
TensorFlow
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to error will be raised if a numpy array is created with a shape such that one element is zero and the others sum to a large number. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.