{"id":"CVE-2022-41900","summary":"FractionalMaxPool and FractionalAVGPool heap out-of-bounds acess in Tensorflow","details":"TensorFlow is an open source platform for machine learning. The security vulnerability results in FractionalMax(AVG)Pool with illegal pooling_ratio. Attackers using Tensorflow can exploit the vulnerability. They can access heap memory which is not in the control of user, leading to a crash or remote code execution. We have patched the issue in GitHub commit 216525144ee7c910296f5b05d214ca1327c9ce48. The fix will be included in TensorFlow 2.11.0. We will also cherry pick this commit on TensorFlow 2.10.1.","aliases":["BIT-tensorflow-2022-41900","GHSA-xvwp-h6jv-7472","PYSEC-2026-1049","PYSEC-2026-3261","PYSEC-2026-3383"],"modified":"2026-08-12T13:33:23.062453Z","published":"2022-11-18T00:00:00Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-125","CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/41xxx/CVE-2022-41900.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/41xxx/CVE-2022-41900.json"},{"type":"ADVISORY","url":"https://github.com/tensorflow/tensorflow/security/advisories/GHSA-xvwp-h6jv-7472"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-41900"},{"type":"FIX","url":"https://github.com/tensorflow/tensorflow/commit/216525144ee7c910296f5b05d214ca1327c9ce48"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tensorflow/tensorflow","events":[{"introduced":"0"},{"fixed":"1b8f5c396f0c016ebe81fe1af029e6f205c926a4"},{"introduced":"8a20d54a3c1bfa38c03ea99a2ad3c1b0a45dfa95"},{"fixed":"a5ed5f39b675a1c6f315e0caf3ad4b38478fa571"},{"introduced":"359c3cdfc5fabac82b3c70b3b6de2b0a8c16874f"},{"fixed":"216525144ee7c910296f5b05d214ca1327c9ce48"}],"database_specific":{"cpe":["cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:*","cpe:2.3:a:google:tensorflow:2.10.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"2.8.4"},{"introduced":"2.9.0"},{"fixed":"2.9.3"},{"introduced":"2.10.0"},{"last_affected":"2.10.0"}],"source":["CPE_RANGE","CPE_STRING","REFERENCES"]}}],"versions":["2.10.0","v2.8.3","v2.9.2","v2.8.2","v2.9.1","v2.8.1","v2.9.0","v2.8.0","v2.8.0-rc1","v2.8.0-rc0","v1.12.1","v1.9.0-rc2","v1.6.0-rc1","v1.1.0-rc2","v1.1.0-rc1","0.6.0","0.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-41900.json","vanir_signatures_modified":"2026-08-12T13:33:23Z","vanir_signatures":[{"source":"https://github.com/tensorflow/tensorflow/commit/216525144ee7c910296f5b05d214ca1327c9ce48","target":{"file":"tensorflow/core/ops/nn_ops.cc"},"deprecated":false,"digest":{"line_hashes":["325296704341259377050807897249101124081","155891448976628834569700771673825553745","165766134740372561709145310176512224040"],"threshold":0.9},"id":"CVE-2022-41900-00af93cb","signature_type":"Line","signature_version":"v1"},{"deprecated":false,"digest":{"length":952,"function_hash":"320529571845476723401494652116537370619"},"id":"CVE-2022-41900-06a6a2a1","signature_type":"Function","signature_version":"v1","source":"https://github.com/tensorflow/tensorflow/commit/216525144ee7c910296f5b05d214ca1327c9ce48","target":{"file":"tensorflow/core/ops/nn_ops.cc","function":"FractionalPoolShapeFn"}},{"digest":{"line_hashes":["336970152307701500643505373335486396169","116674744995192051606672386349114925707","177583138458568330568069971963290062431","332878879180634489725428648848377535514","179309074459589736330955723405307809197","137516537461930727700999729154222366494","335752277757375044442737913551379721594","12866893923829577425179712936381248417","322990942685987054101028840592906027670","260589313693383649707643589123931363454","229427688290951882864366779470611092521","132377005675449145846788285401133419680"],"threshold":0.9},"id":"CVE-2022-41900-32a8a4b2","signature_type":"Line","signature_version":"v1","source":"https://github.com/tensorflow/tensorflow/commit/216525144ee7c910296f5b05d214ca1327c9ce48","target":{"file":"tensorflow/core/ops/nn_ops_test.cc"},"deprecated":false},{"digest":{"line_hashes":["230808465806769864172395955091572870244","328181973501586450465866470564667299278","43263722418441609933506727502125146383","279326865201226645095600693438657321512","50938593015776107771649365484750030369","297071598841061122185097826497031668719","327067942636835449385663073639413216626","158555329534275234373551648347560314080","143524025643664346037004426768206345967","312808564032835685377695130996068937664"],"threshold":0.9},"id":"CVE-2022-41900-72d8efae","signature_type":"Line","signature_version":"v1","source":"https://github.com/tensorflow/tensorflow/commit/216525144ee7c910296f5b05d214ca1327c9ce48","target":{"file":"tensorflow/core/kernels/fractional_avg_pool_op.cc"},"deprecated":false},{"digest":{"function_hash":"284473343337579778620519781184376668143","length":1234},"id":"CVE-2022-41900-bb6338e9","signature_type":"Function","signature_version":"v1","source":"https://github.com/tensorflow/tensorflow/commit/216525144ee7c910296f5b05d214ca1327c9ce48","target":{"file":"tensorflow/core/ops/nn_ops_test.cc","function":"TEST"},"deprecated":false},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/tensorflow/tensorflow/commit/216525144ee7c910296f5b05d214ca1327c9ce48","target":{"file":"tensorflow/core/kernels/fractional_max_pool_op.cc"},"deprecated":false,"digest":{"line_hashes":["113537114069758900818270817557871553967","300056429406537556478293400253326243884","82760606382510668210546968679606915609","131796142506958427639680036357599122576"],"threshold":0.9},"id":"CVE-2022-41900-eb175f4b"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"}]}