Tensorflow is an Open Source Machine Learning Framework. The `GraphDef` format in TensorFlow does not allow self recursive functions. The runtime assumes that this invariant is satisfied. However, a `GraphDef` containing a fragment such as the following can be consumed when loading a `SavedModel`. This would result in a stack overflow during execution as resolving each `NodeDef` means resolving the function itself and its nodes. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow 2.6.3, and TensorFlow 2.5.3, as these are also affected and still in supported range.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2022-02-04T22:32:09
Updated: 2024-08-03T03:43:46.959Z
Reserved: 2022-01-19T00:00:00
Link: CVE-2022-23591
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-02-04T23:15:15.253
Modified: 2024-11-21T06:48:52.990
Link: CVE-2022-23591
Redhat
No data.