{"id":"CVE-2022-21740","summary":"Heap overflow in Tensorflow","details":"Tensorflow is an Open Source Machine Learning Framework. The implementation of `SparseCountSparseOutput` is vulnerable to a heap overflow. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow 2.6.3, and TensorFlow 2.5.3, as these are also affected and still in supported range.","aliases":["BIT-tensorflow-2022-21740","GHSA-44qp-9wwf-734r","PYSEC-2022-119","PYSEC-2022-64","PYSEC-2026-3097"],"modified":"2026-08-12T12:59:46.161500Z","published":"2022-02-03T14:30:47Z","related":["openSUSE-SU-2024:12116-1"],"database_specific":{"cna_assigner":"GitHub_M","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/21xxx/CVE-2022-21740.json"},"references":[{"type":"WEB","url":"https://github.com/tensorflow/tensorflow/blob/5100e359aef5c8021f2e71c7b986420b85ce7b3d/tensorflow/core/kernels/count_ops.cc#L168-L273"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/21xxx/CVE-2022-21740.json"},{"type":"ADVISORY","url":"https://github.com/tensorflow/tensorflow/security/advisories/GHSA-44qp-9wwf-734r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-21740"},{"type":"FIX","url":"https://github.com/tensorflow/tensorflow/commit/2b7100d6cdff36aa21010a82269bc05a6d1cc74a"},{"type":"FIX","url":"https://github.com/tensorflow/tensorflow/commit/adbbabdb0d3abb3cdeac69e38a96de1d678b24b3"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tensorflow/tensorflow","events":[{"introduced":"0"},{"last_affected":"957590ea15cc03ee2e00fc61934647d54836676f"},{"introduced":"919f693420e35d00c8d0a42100837ae3718f7927"},{"last_affected":"c2363d6d025981c661f8cbecf4c73ca7fbf38caf"},{"introduced":"c256c071bb26e1e13b4666d1b3e229e110bc914a"},{"fixed":"2b7100d6cdff36aa21010a82269bc05a6d1cc74a"},{"fixed":"adbbabdb0d3abb3cdeac69e38a96de1d678b24b3"}],"database_specific":{"cpe":["cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:*","cpe:2.3:a:google:tensorflow:2.7.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"2.5.2"},{"introduced":"2.6.0"},{"last_affected":"2.6.2"},{"introduced":"2.7.0"},{"last_affected":"2.7.0"}],"source":["CPE_RANGE","CPE_STRING","REFERENCES"]}}],"versions":["2.7.0","v2.5.2","v2.6.2","v2.6.1","v2.6.0","v2.5.1","v2.5.0","v2.5.0-rc3","v2.5.0-rc2","v2.5.0-rc1","v2.5.0-rc0","v1.12.1","v1.9.0-rc2","v1.6.0-rc1","v1.1.0-rc2","v1.1.0-rc1","0.6.0","0.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-21740.json","vanir_signatures_modified":"2026-08-12T12:59:46Z","vanir_signatures":[{"source":"https://github.com/tensorflow/tensorflow/commit/2b7100d6cdff36aa21010a82269bc05a6d1cc74a","target":{"file":"tensorflow/core/kernels/count_ops.cc"},"deprecated":false,"digest":{"line_hashes":["122268366615870984061731212483338613608","331197975007086142495442295116876276889","274333202759242867661362820132762296942","24540839225558138880736723824630938445","54986795225819630183321432706554493921","111387036045776398925780042773652253108","236414246192172195641386631347115688475","331528481227994275889744815991125017247","270153746900716505495932950264790376392","12092929553094343785797268482198443203","7874507959324440005089441570945882077","70292989773184290943277274873153948233","37784336467189883900985648367146805012","78255415891508767832834393378684214991","119301024285150303581569650604645531891","242432251648936141967772996842232720327","80743426556312547582870807565152435026","305542167729994706683797306584931349203","113972689815413783749537851093374806771","15095870996015274044393628556655552557","88406783310725338448377167891769338516","176815940850939357411414247040828562788","282861960725116743484462341347643923394","245670380746282353972333627797044514944","145240645846633392420339396997140337622","142502283888192935441185518778031548263","286146451268294583632579489631235618492","242813962013336255070449395816118815813","323975600079809876117292672000661218444","148200533338745609053035860708214667501","280770808928017248684546375780452873765","167428460600871771954203503171272625576","51280031490941488587456689041229912459","61473214249927899287073148589492835079","211611697522199923154704004340082255571","314009107591415659434262482843296394448","3878503606720120236402875860279767962"],"threshold":0.9},"id":"CVE-2022-21740-f56d89b8","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H"}]}