{"schema_version":"1.9.0","id":"CVE-2022-23564","published":"2022-02-04T22:32:41Z","modified":"2026-08-12T12:59:53.362825Z","aliases":["BIT-tensorflow-2022-23564","GHSA-8rcj-c8pj-v3m3","PYSEC-2022-128","PYSEC-2022-73","PYSEC-2026-3139"],"related":["openSUSE-SU-2024:12116-1"],"summary":"Reachable Assertion in Tensorflow","details":"Tensorflow is an Open Source Machine Learning Framework. When decoding a resource handle tensor from protobuf, a TensorFlow process can encounter cases where a `CHECK` assertion is invalidated based on user controlled arguments. This allows attackers to cause denial of services in TensorFlow processes. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow 2.6.3, and TensorFlow 2.5.3, as these are also affected and still in supported range.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tensorflow/tensorflow","events":[{"introduced":"0"},{"last_affected":"957590ea15cc03ee2e00fc61934647d54836676f"},{"introduced":"919f693420e35d00c8d0a42100837ae3718f7927"},{"last_affected":"c2363d6d025981c661f8cbecf4c73ca7fbf38caf"},{"introduced":"c256c071bb26e1e13b4666d1b3e229e110bc914a"},{"fixed":"14fea662350e7c26eb5fe1be2ac31704e5682ee6"}],"database_specific":{"cpe":["cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:*","cpe:2.3:a:google:tensorflow:2.7.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"2.5.2"},{"introduced":"2.6.0"},{"last_affected":"2.6.2"},{"introduced":"2.7.0"},{"last_affected":"2.7.0"}],"source":["CPE_RANGE","CPE_STRING","REFERENCES"]}}],"versions":["2.7.0","v2.5.2","v2.6.2","v2.6.1","v2.6.0","v2.5.1","v2.5.0","v2.5.0-rc3","v2.5.0-rc2","v2.5.0-rc1","v2.5.0-rc0","v1.12.1","v1.9.0-rc2","v1.6.0-rc1","v1.1.0-rc2","v1.1.0-rc1","0.6.0","0.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23564.json","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"153987315558091852620372711404783651806","length":503},"id":"CVE-2022-23564-0acdfdb5","signature_type":"Function","signature_version":"v1","source":"https://github.com/tensorflow/tensorflow/commit/14fea662350e7c26eb5fe1be2ac31704e5682ee6","target":{"file":"tensorflow/core/framework/resource_handle.cc","function":"ResourceHandle::FromProto"}},{"deprecated":false,"digest":{"line_hashes":["246955572514573924807537689989783715350","241861728870523561215564888176747173438","49473206892218221533860985750701486890","111860022852385134031922976015851927826","329530622018296717534769405516973089401","70554690193637018345756269759940395799","46733267529274400295748657644110611803"],"threshold":0.9},"id":"CVE-2022-23564-8e0134fd","signature_type":"Line","signature_version":"v1","source":"https://github.com/tensorflow/tensorflow/commit/14fea662350e7c26eb5fe1be2ac31704e5682ee6","target":{"file":"tensorflow/core/framework/resource_handle.h"}},{"deprecated":false,"digest":{"line_hashes":["121970794250698732413675609961490408927","320017457721990977676022283387235771435","193013501273046047834777044903739164227","82448484681600333511975630210507559702","277106902844166404186640664674512164060","319064233247399589840571860933320861969","328258278304958452525391048272355888793","59822815218775027696539377410426848658","127269457319388520020109472237739248935","132805316669767322023850050145564769326","211680169678225084319673317321921481231","332188347260563990636568670992081544309","54594564179875383761012854051104599999","306320113071682141665875485629394338994","281061334505761134219287296897573250716","252997270884773007713001274796216214180","217127341608800203452154721703196477155","40234439256165692379620160778204648142","338361110094881129850820255919140602376","106995960596016699172785527414693241427","32455975475837853917135786466913914255","9937590439596796379479851749337082728","283628656536069881246468267275990874040","149469555853987245837660558991966736401","212381437676195754385219224792336534668","302686529296299069242335578289215941214","312291174835468390388444791579595909967","150585291733013666452358606394493474250","295907500653578005849423161238793786657","167042890378280469287218090845302668270"],"threshold":0.9},"id":"CVE-2022-23564-b94ccc22","signature_type":"Line","signature_version":"v1","source":"https://github.com/tensorflow/tensorflow/commit/14fea662350e7c26eb5fe1be2ac31704e5682ee6","target":{"file":"tensorflow/core/framework/resource_handle.cc"}},{"deprecated":false,"digest":{"function_hash":"86001461152611799129681606208426486701","length":174},"id":"CVE-2022-23564-c917d4bd","signature_type":"Function","signature_version":"v1","source":"https://github.com/tensorflow/tensorflow/commit/14fea662350e7c26eb5fe1be2ac31704e5682ee6","target":{"file":"tensorflow/core/framework/resource_handle.cc","function":"ResourceHandle::ParseFromString"}},{"deprecated":false,"digest":{"function_hash":"199728409571945858538508641889054544046","length":81},"id":"CVE-2022-23564-f0cc8560","signature_type":"Function","signature_version":"v1","source":"https://github.com/tensorflow/tensorflow/commit/14fea662350e7c26eb5fe1be2ac31704e5682ee6","target":{"file":"tensorflow/core/framework/resource_handle.cc","function":"ResourceHandle::ResourceHandle"}}],"vanir_signatures_modified":"2026-08-12T12:59:53Z"}}],"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23564.json"},{"type":"ADVISORY","url":"https://github.com/tensorflow/tensorflow/security/advisories/GHSA-8rcj-c8pj-v3m3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23564"},{"type":"FIX","url":"https://github.com/tensorflow/tensorflow/commit/14fea662350e7c26eb5fe1be2ac31704e5682ee6"}],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-617"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23564.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}