<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T09:35:27.723581+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2022-23559</id>
    <title>CVE-2022-23559 — Integer overflow in TFLite</title>
    <updated>2026-10-06T09:35:27.725367+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> tensorflow</p>
<p>Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause an integer overflow in embedding lookup operations. Both `embedding_size` and `lookup_size` are products of values provided by the user. Hence, a malicious user could trigger overflows in the multiplication. In certain scenarios, this can then result in heap OOB read/write. Users are advised to upgrade to a patched version.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2022-23559"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-98p5-x8x4-c9m5</id>
    <title>GHSA-98p5-x8x4-c9m5 — Integer overflow in TFLite</title>
    <updated>2026-10-06T09:35:27.725419+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: tensorflow, PyPI: tensorflow-cpu, PyPI: tensorflow-gpu</p>
<p>### Impact 
An attacker can craft a TFLite model that would cause an integer overflow [in embedding lookup operations](https://github.com/tensorflow/tensorflow/blob/ca6f96b62ad84207fbec580404eaa7dd7403a550/tensorflow/lite/kernels/embedding_lookup_sparse.cc#L179-L189):</p>
<p>```cc
  int embedding_size = 1;
  int lookup_size = 1;
  for (int i = 0; i &lt; lookup_rank - 1; i++, k++) {
    const int dim = dense_shape-&gt;data.i32[i];
    lookup_size *= dim;
    output_shape-&gt;data[k] = dim;
  }
  for (int i = 1; i &lt; embedding_rank; i++, k++) {
    const int dim = SizeOfDimension(value, i);
    embedding_size *= dim;
    output_shape-&gt;data[k] = dim;
  } 
```</p>
<p>Both `embedding_size` and `lookup_size` are products of values provided by the user. Hence, a malicious user could trigger overflows in the multiplication.</p>
<p>In certain scenarios, this can then result in heap OOB read/write.
  
### Patches
We have patched the issue in GitHub commits [f19be71717c497723ba0cea0379e84f061a75e01](https://github.com/tensorflow/tensorflow/commit/f19be71717c497723ba0cea0379e84f061a75e01), [1de49725a5fc4e48f1a3b902ec3599ee99283043](https://github.com/tensorflow/tensorflow/commit/1de49725a5fc4e48f1a3b902ec3599ee99283043) and [a4e401da71458d253b05e41f28637b65baf64be4](https://github.com/tensorflow/tensorflow/commit/a4e401da71458d253b05e41f28637b65baf64be4).</p>
<p>The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow 2.6.3, and TensorFlow 2.5.3, as these are also…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-98p5-x8x4-c9m5"/>
  </entry>
</feed>
