Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause an integer overflow in embedding lookup operations. Both `embedding_size` and `lookup_size` are products of values provided by the user. Hence, a malicious user could trigger overflows in the multiplication. In certain scenarios, this can then result in heap OOB read/write. Users are advised to upgrade to a patched version.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2022-02-04T22:32:37

Updated: 2022-02-04T22:32:37

Reserved: 2022-01-19T00:00:00


Link: CVE-2022-23559

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-02-04T23:15:13.673

Modified: 2022-02-09T18:53:03.463


Link: CVE-2022-23559

JSON object: View

cve-icon Redhat Information

No data.

CWE