Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. tensorflow
  4. ›
  5. CVE-2022-21741

CVE-2022-21741: Division by zero in TFLite

February 9, 2022 (updated November 13, 2024)

An attacker can craft a TFLite model that would trigger a division by zero in the implementation of depthwise convolutions.

The parameters of the convolution can be user controlled and are also used within a division operation to determine the size of the padding that needs to be added before applying the convolution. There is no check before this division that the divisor is stricly positive.

References

  • github.com/advisories/GHSA-428x-9xc2-m8mj
  • github.com/pypa/advisory-database/tree/main/vulns/tensorflow-cpu/PYSEC-2022-65.yaml
  • github.com/pypa/advisory-database/tree/main/vulns/tensorflow-gpu/PYSEC-2022-120.yaml
  • github.com/tensorflow/tensorflow
  • github.com/tensorflow/tensorflow/blob/5100e359aef5c8021f2e71c7b986420b85ce7b3d/tensorflow/lite/kernels/depthwise_conv.cc
  • github.com/tensorflow/tensorflow/commit/e5b0eec199c2d03de54fd6a7fd9275692218e2bc
  • github.com/tensorflow/tensorflow/security/advisories/GHSA-428x-9xc2-m8mj
  • nvd.nist.gov/vuln/detail/CVE-2022-21741

Code Behaviors & Features

Detect and mitigate CVE-2022-21741 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.5.3, all versions starting from 2.6.0 before 2.6.3, all versions starting from 2.7.0 before 2.7.1, version 2.7.0

Fixed versions

  • 2.5.3
  • 2.6.3
  • 2.7.1

Solution

Upgrade to versions 2.5.3, 2.6.3, 2.7.1 or above.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-369: Divide By Zero

Source file

pypi/tensorflow/CVE-2022-21741.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:09 +0000.