Home » Database

AVID-2026-R0993

Description

Segfault in simplifyBroadcast in Tensorflow (CVE-2022-23593)

Details

Tensorflow is an Open Source Machine Learning Framework. The simplifyBroadcast function in the MLIR-TFRT infrastructure in TensorFlow is vulnerable to a segfault (hence, denial of service), if called with scalar shapes. If all shapes are scalar, then maxRank is 0, so we build an empty SmallVector. The fix will be included in TensorFlow 2.8.0. This is the only affected version.

Reason for inclusion in AVID: CVE-2022-23593 describes a segfault vulnerability in TensorFlow’s MLIR-TFRT path that can cause denial of service when invoked with scalar shapes. TensorFlow is a core AI/ML framework, and this vulnerability affects software used to build/train/deploy AI systems, impacting the AI software supply chain. The report includes CVE details, affected components, and a fix timeline, providing clear evidence for inclusion.

References

Affected or Relevant Artifacts

  • Developer: tensorflow
  • Deployer: tensorflow
  • Artifact Details:
TypeName
Systemtensorflow

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.1
Vector StringCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score5.9
Base Severity🟠 Medium
Attack VectorNETWORK
Attack Complexity🔴 High
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability Impact🔴 High

CWE

IDDescription
CWE-754CWE-754: Improper Check for Unusual or Exceptional Conditions

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2022-02-04
  • Version: 0.3.3
  • AVID Entry