Executive brief
TensorFlow's UnravelIndex operation, a utility function used to convert flat indices into multidimensional coordinates, is vulnerable to a division by zero error triggered by integer overflow. An attacker with the ability to call this operation directly can crash a TensorFlow application, causing denial of service and disrupting machine learning inference or training workloads.
Technical details
The vulnerability exists in the UnravelIndex operation due to an integer overflow (CWE-190) that leads to an uncaught division by zero. The flaw occurs when processing specially crafted negative indices and dimension parameters, as demonstrated in the proof of concept: `tf.raw_ops.UnravelIndex(indices=-0x100000, dims=[0x100000, 0x100000])`. The attack requires direct access to call TensorFlow operations, typically achievable only by applications that accept untrusted model code or tensor inputs. Successful exploitation causes an unhandled exception that terminates the process. Patches are available in TensorFlow 2.5.3, 2.6.3, 2.7.1, and 2.8.0+.
Affected products
- Google TensorFlow all versions before 2.5.3, 2.6.x before 2.6.3, 2.7.0
Timeline
- 2022-02-02: disclosed
- 2022-02-10: patched: Patches released for 2.5.3, 2.6.3, 2.7.1; fix included in 2.8.0