{"schema_version":"1.9.0","id":"CVE-2022-23558","published":"2022-02-04T22:32:43Z","modified":"2026-08-12T12:59:52.454596Z","aliases":["BIT-tensorflow-2022-23558","GHSA-9gwq-6cwj-47h3","PYSEC-2022-122","PYSEC-2022-67","PYSEC-2026-3151"],"related":["openSUSE-SU-2024:12116-1"],"summary":"Integer overflow in TFLite array creation","details":"Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause an integer overflow in `TfLiteIntArrayCreate`. The `TfLiteIntArrayGetSizeInBytes` returns an `int` instead of a `size_t. An attacker can control model inputs such that `computed_size` overflows the size of `int` datatype. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow 2.6.3, and TensorFlow 2.5.3, as these are also affected and still in supported range.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tensorflow/tensorflow","events":[{"introduced":"0"},{"last_affected":"957590ea15cc03ee2e00fc61934647d54836676f"},{"introduced":"919f693420e35d00c8d0a42100837ae3718f7927"},{"last_affected":"c2363d6d025981c661f8cbecf4c73ca7fbf38caf"},{"introduced":"c256c071bb26e1e13b4666d1b3e229e110bc914a"},{"fixed":"a1e1511dde36b3f8aa27a6ec630838e7ea40e091"}],"database_specific":{"cpe":["cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:*","cpe:2.3:a:google:tensorflow:2.7.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"2.5.2"},{"introduced":"2.6.0"},{"last_affected":"2.6.2"},{"introduced":"2.7.0"},{"last_affected":"2.7.0"}],"source":["CPE_RANGE","CPE_STRING","REFERENCES"]}}],"versions":["2.7.0","v2.5.2","v2.6.2","v2.6.1","v2.6.0","v2.5.1","v2.5.0","v2.5.0-rc3","v2.5.0-rc2","v2.5.0-rc1","v2.5.0-rc0","v1.12.1","v1.9.0-rc2","v1.6.0-rc1","v1.1.0-rc2","v1.1.0-rc1","0.6.0","0.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23558.json","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["171574500459875443604848124624218915802","224402572128596711426760887297223854329","135810787384557766327668633486589560300","52906517305869918692868499887876669595"],"threshold":0.9},"id":"CVE-2022-23558-0f4a9ea1","signature_type":"Line","signature_version":"v1","source":"https://github.com/tensorflow/tensorflow/commit/a1e1511dde36b3f8aa27a6ec630838e7ea40e091","target":{"file":"tensorflow/lite/c/common.h"}},{"deprecated":false,"digest":{"line_hashes":["303182263945096448503942580283856288815","211472108754273992845089260881158983328","68180377537374127555831513198225263551","110871423983210532081698651103909080455","310632343255929382883034487929488782723","316708293277310007548091378489176229496","235791973948306355285272286755673464651","7432712228470703914669726949789771089","250519190024000099250858355888427817708","290119360993927202194119368295700812061"],"threshold":0.9},"id":"CVE-2022-23558-e7e6b9a1","signature_type":"Line","signature_version":"v1","source":"https://github.com/tensorflow/tensorflow/commit/a1e1511dde36b3f8aa27a6ec630838e7ea40e091","target":{"file":"tensorflow/lite/c/common.c"}}],"vanir_signatures_modified":"2026-08-12T12:59:52Z"}}],"references":[{"type":"WEB","url":"https://github.com/tensorflow/tensorflow/blob/ca6f96b62ad84207fbec580404eaa7dd7403a550/tensorflow/lite/c/common.c#L24-L33"},{"type":"WEB","url":"https://github.com/tensorflow/tensorflow/blob/ca6f96b62ad84207fbec580404eaa7dd7403a550/tensorflow/lite/c/common.c#L53-L60"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23558.json"},{"type":"ADVISORY","url":"https://github.com/tensorflow/tensorflow/security/advisories/GHSA-9gwq-6cwj-47h3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23558"},{"type":"FIX","url":"https://github.com/tensorflow/tensorflow/commit/a1e1511dde36b3f8aa27a6ec630838e7ea40e091"}],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-190"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23558.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H"}]}