Executive brief
TensorFlow is a machine learning framework used to build and train neural networks. When the Conv2DBackpropInput operation receives specially crafted empty input data, the framework crashes due to a failed internal safety check, allowing an attacker to cause a denial of service by interrupting model training or inference operations.
Technical details
This vulnerability is a CHECK fail (assertion failure) in the Conv2DBackpropInput operation when processing empty out_backprop tensors with dimensions like [3, 1, 0, 1]. The root cause is insufficient input validation before processing in both CPU (dnnl) and GPU (cudnn) kernels. An attacker can trigger this by calling tf.raw_ops.Conv2DBackpropInput with crafted tensor dimensions, causing the process to abort. No authentication is required; the operation is network-accessible if exposed via a TensorFlow Serving endpoint or similar deployment. The fix adds proper validation of input dimensions before processing, included in TensorFlow 2.10.0 and backported to 2.9.1, 2.8.1, and 2.7.2.
Affected products
- Google TensorFlow < 2.10.0; specifically 0.12.0 through 2.7.1, 2.8.0, 2.9.0
- Google TensorFlow CPU < 2.8.1; specifically 1.15.0 through 2.7.1, 2.8.0
- Google TensorFlow GPU < 2.10.0; specifically 0.12.0 through 2.7.1, 2.8.0, 2.9.0
Timeline
- 2022-09-16: disclosed
- 2022-09-16: patched: Fix included in TensorFlow 2.10.0; backported to 2.9.1, 2.8.1, and 2.7.2