Home » Database

AVID-2026-R1030

Description

Undefined behavior when users supply invalid resource handles in TensorFlow (CVE-2022-29207)

Details

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, multiple TensorFlow operations misbehave in eager mode when the resource handle provided to them is invalid. In graph mode, it would have been impossible to perform these API calls, but migration to TF 2.x eager mode opened up this vulnerability. If the resource handle is empty, then a reference is bound to a null pointer inside TensorFlow codebase (various codepaths). This is undefined behavior. Versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4 contain a patch for this issue.

Reason for inclusion in AVID: CVE-2022-29207 describes a software vulnerability in TensorFlow, a core ML framework used in AI pipelines. It affects eager-mode operations when given invalid resource handles, potentially causing undefined behavior and availability impact. TensorFlow is a central component used to build/train/deploy AI systems, so this is a software supply-chain risk for general-purpose AI systems. The report provides affected versions (2.6.4, 2.7.2, 2.8.1, 2.9.0) and patches, along with CVSS details and CWE mappings, giving sufficient evidence for classification.

References

Affected or Relevant Artifacts

  • Developer: tensorflow
  • Deployer: tensorflow
  • Artifact Details:
TypeName
Systemtensorflow

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.1
Vector StringCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score5.5
Base Severity🟠 Medium
Attack VectorLOCAL
Attack Complexity🟢 Low
Privileges Required🟢 Low
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability Impact🔴 High

CWE

IDDescription
CWE-20CWE-20: Improper Input Validation
CWE-475CWE-475: Undefined Behavior for Input to API

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2022-05-20
  • Version: 0.3.3
  • AVID Entry