Executive brief
TensorFlow's EditDistance operation is used for computing string similarity metrics in machine learning models. An attacker can pass specially crafted negative values to trigger a segmentation fault or corrupt memory by writing outside array bounds, causing service crashes or potential code execution in applications that process untrusted input.
Technical details
The vulnerability exists in tf.raw_ops.EditDistance due to incomplete input validation. The operation computes an array write index using std::inner_product but validates only the upper bound, allowing negative indices when crafted with negative input values. This results in out-of-bounds writes before the allocated buffer, causing either segmentation faults (denial of service) or memory corruption. The vulnerability affects all versions prior to TensorFlow 2.6.4, with patches available for 2.6.4, 2.7.2, 2.8.1, and 2.9.0. Exploitation requires local access and ability to invoke the EditDistance operation with untrusted parameters.
Affected products
- Google TensorFlow prior to 2.6.4, 2.7.0-2.7.1, 2.8.0
- Google TensorFlow CPU 1.15.0, 2.1.0-2.1.4, 2.2.0-2.2.3, 2.3.0-2.3.4, 2.4.0-2.4.4, 2.5.0-2.5.3, 2.6.0-2.6.3
Timeline
- 2022-05-24: disclosed
- 2022-05-24: patched: Patches released for TensorFlow 2.6.4, 2.7.2, 2.8.1, and 2.9.0