Executive brief
TensorFlow's average pooling gradient operation (AvgPoolGrad) fails to properly validate input tensor dimensions, allowing an attacker to trigger a denial-of-service crash by supplying invalid input shapes. This can disrupt machine learning applications that rely on TensorFlow for training or inference.
Technical details
The vulnerability is a missing input validation bug (CWE-617) in the AvgPoolGrad operation of TensorFlow. The operation does not fully validate the orig_input_shape parameter before using it, causing an unhandled CHECK failure (assertion failure) that terminates the process. An attacker can trigger this by calling tf.raw_ops.AvgPoolGrad with a maliciously crafted orig_input_shape tensor containing invalid values (e.g., negative dimensions). The attack requires network access only if the TensorFlow model is exposed via a service; no authentication or user interaction is needed. The impact is denial of service through application crash. Patches have been released in TensorFlow 2.7.2, 2.8.1, 2.9.1, and 2.10.0.
Affected products
- Google TensorFlow all versions before 2.7.2; 2.8.0; 2.9.0
- Google TensorFlow CPU all versions before 2.7.2; 2.8.0; 2.9.0
- Google TensorFlow GPU all versions before 2.7.2; 2.8.0; 2.9.0
Timeline
- 2022-09-16: disclosed: Vulnerability advisory published
- 2022-09-16: patched: Fix committed in GitHub; patches released for TensorFlow 2.7.2, 2.8.1, 2.9.1, 2.10.0