{"schema_version":"1.9.0","id":"CVE-2022-21729","published":"2022-02-03T12:28:25Z","modified":"2026-08-12T12:59:46.461480Z","aliases":["BIT-tensorflow-2022-21729","GHSA-34f9-hjfq-rr8j","PYSEC-2022-108","PYSEC-2022-53","PYSEC-2026-3090"],"related":["openSUSE-SU-2024:12116-1"],"summary":"Overflow and uncaught divide by zero in Tensorflow","details":"Tensorflow is an Open Source Machine Learning Framework. The implementation of `UnravelIndex` is vulnerable to a division by zero caused by an integer overflow bug. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow 2.6.3, and TensorFlow 2.5.3, as these are also affected and still in supported range.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tensorflow/tensorflow","events":[{"introduced":"0"},{"last_affected":"957590ea15cc03ee2e00fc61934647d54836676f"},{"introduced":"919f693420e35d00c8d0a42100837ae3718f7927"},{"last_affected":"c2363d6d025981c661f8cbecf4c73ca7fbf38caf"},{"introduced":"c256c071bb26e1e13b4666d1b3e229e110bc914a"},{"fixed":"58b34c6c8250983948b5a781b426f6aa01fd47af"}],"database_specific":{"cpe":["cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:*","cpe:2.3:a:google:tensorflow:2.7.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"2.5.2"},{"introduced":"2.6.0"},{"last_affected":"2.6.2"},{"introduced":"2.7.0"},{"last_affected":"2.7.0"}],"source":["CPE_RANGE","CPE_STRING","REFERENCES"]}}],"versions":["2.7.0","v2.5.2","v2.6.2","v2.6.1","v2.6.0","v2.5.1","v2.5.0","v2.5.0-rc3","v2.5.0-rc2","v2.5.0-rc1","v2.5.0-rc0","v1.12.1","v1.9.0-rc2","v1.6.0-rc1","v1.1.0-rc2","v1.1.0-rc1","0.6.0","0.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-21729.json","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["1444218853322332737553807505921997442","70227620433608194557194791093428629634","311980521188834628803016558772345585653","123149088140680511294079204751680307404","237736702875218587225422321412793671176","135889393770756176031101482765715858234","307426493925868074274405354099294167239","16558284891228274038522441324874245381","54740231733875569198094292010724024967","70608901947208096443923787499729028280","145864460975070558682250576726408054307","131344307614399446808192196414469523510","331769581959027635861349972341503292989","100746938046050783909126814280737664893","207764313565646815348081725156903200790","165578325870109916258041301903980610512","300219599044143289681939827422074987641","292315714547925038791102393509546373971"],"threshold":0.9},"id":"CVE-2022-21729-bf356d77","signature_type":"Line","signature_version":"v1","source":"https://github.com/tensorflow/tensorflow/commit/58b34c6c8250983948b5a781b426f6aa01fd47af","target":{"file":"tensorflow/core/kernels/unravel_index_op.cc"}}],"vanir_signatures_modified":"2026-08-12T12:59:46Z"}}],"references":[{"type":"WEB","url":"https://github.com/tensorflow/tensorflow/blob/5100e359aef5c8021f2e71c7b986420b85ce7b3d/tensorflow/core/kernels/unravel_index_op.cc#L36-L135"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/21xxx/CVE-2022-21729.json"},{"type":"ADVISORY","url":"https://github.com/tensorflow/tensorflow/security/advisories/GHSA-34f9-hjfq-rr8j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-21729"},{"type":"FIX","url":"https://github.com/tensorflow/tensorflow/commit/58b34c6c8250983948b5a781b426f6aa01fd47af"}],"database_specific":{"cna_assigner":"GitHub_M","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/21xxx/CVE-2022-21729.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}