Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause an integer overflow in embedding lookup operations. Both `embedding_size` and `lookup_size` are products of values provided by the user. Hence, a malicious user could trigger overflows in the multiplication. In certain scenarios, this can then result in heap OOB read/write. Users are advised to upgrade to a patched version.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2022-02-04T22:32:37

Updated: 2024-08-03T03:43:46.566Z

Reserved: 2022-01-19T00:00:00

Link: CVE-2022-23559

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-02-04T23:15:13.673

Modified: 2022-02-09T18:53:03.463

Link: CVE-2022-23559

cve-icon Redhat

No data.