CVE Vulnerabilities

CVE-2022-21735

Divide By Zero

Published: Feb 03, 2022 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

Tensorflow is an Open Source Machine Learning Framework. The implementation of FractionalMaxPool can be made to crash a TensorFlow process via a division by 0. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow 2.6.3, and TensorFlow 2.5.3, as these are also affected and still in supported range.

Weakness

The product divides a value by zero.

Affected Software

Name Vendor Start Version End Version
Tensorflow Google * 2.5.2 (including)
Tensorflow Google 2.6.0 (including) 2.6.2 (including)
Tensorflow Google 2.7.0 (including) 2.7.0 (including)

References