Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause an integer overflow in embedding lookup operations. Both `embedding_size` and `lookup_size` are products of values provided by the user. Hence, a malicious user could trigger overflows in the multiplication. In certain scenarios, this can then result in heap OOB read/write. Users are advised to upgrade to a patched version.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2022-02-04T22:32:37
Updated: 2024-08-03T03:43:46.566Z
Reserved: 2022-01-19T00:00:00
Link: CVE-2022-23559
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-02-04T23:15:13.673
Modified: 2024-11-21T06:48:48.760
Link: CVE-2022-23559
Redhat
No data.