Junglewise Threat Intelligence

CVE-2022-23584: PYSEC-2026-3085 - Use after free in `DecodePng` kernel

CVE-2022-23584 · Severity: low · CVSS 3.1 · Published 2026-07-09

Technologies: tensorflow (PyPI), tensorflow-cpu (PyPI), Google TensorFlow, tensorflow-gpu (PyPI). Vendors: PyPI, Google.

Executive brief

TensorFlow is a widely-used machine learning library that processes image data as part of its core functionality. A flaw in the PNG image decoding component can cause a program crash or potential data corruption when processing specially crafted PNG files, affecting systems that rely on TensorFlow for image processing tasks.

Technical details

A use-after-free vulnerability exists in the DecodePng kernel's error handling path. When decoding PNG images, if certain error conditions are met (e.g., PNG dimensions exceed integer limits), the code calls png::CommonFreeDecode() to clean up resources, but then attempts to read from freed memory (decode.width and decode.height) in the error message construction. The vulnerability is reachable via PNG image processing without authentication and can be triggered by malicious PNG input. The fix involves moving error checking before resource allocation to prevent the use-after-free. Patches are available in TensorFlow 2.5.3, 2.6.3, 2.7.1, and 2.8.0.

Affected products

  • Google TensorFlow before 2.5.3; 2.6.0-2.6.2; 2.7.0
  • Google TensorFlow CPU before 2.5.3; 2.6.0-2.6.2; 2.7.0
  • Google TensorFlow GPU before 2.5.3; 2.6.0-2.6.2; 2.7.0

Timeline

  • 2022-02-04: disclosed: Vulnerability advisory published
  • 2022-02-09: patched: Patches released in TensorFlow 2.5.3, 2.6.3, 2.7.1, and 2.8.0

References

Related threats