<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 06:54:00 +0000</lastBuildDate>
    <item>
      <title>CVE-2022-23559 — Integer overflow in TFLite</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2022-23559</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; tensorflow&lt;/p&gt;
&lt;p&gt;Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause an integer overflow in embedding lookup operations. Both `embedding_size` and `lookup_size` are products of values provided by the user. Hence, a malicious user could trigger overflows in the multiplication. In certain scenarios, this can then result in heap OOB read/write. Users are advised to upgrade to a patched version.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; tensorflow&lt;/p&gt;
&lt;p&gt;Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause an integer overflow in embedding lookup operations. Both `embedding_size` and `lookup_size` are products of values provided by the user. Hence, a malicious user could trigger overflows in the multiplication. In certain scenarios, this can then result in heap OOB read/write. Users are advised to upgrade to a patched version.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2022-23559</guid>
    </item>
    <item>
      <title>GHSA-98p5-x8x4-c9m5 — Integer overflow in TFLite</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-98p5-x8x4-c9m5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: tensorflow, PyPI: tensorflow-cpu, PyPI: tensorflow-gpu&lt;/p&gt;
&lt;p&gt;### Impact 
An attacker can craft a TFLite model that would cause an integer overflow [in embedding lookup operations](https://github.com/tensorflow/tensorflow/blob/ca6f96b62ad84207fbec580404eaa7dd7403a550/tensorflow/lite/kernels/embedding_lookup_sparse.cc#L179-L189):&lt;/p&gt;
&lt;p&gt;```cc
  int embedding_size = 1;
  int lookup_size = 1;
  for (int i = 0; i &amp;lt; lookup_rank - 1; i++, k++) {
    const int dim = dense_shape-&amp;gt;data.i32[i];
    lookup_size *= dim;
    output_shape-&amp;gt;data[k] = dim;
  }
  for (int i = 1; i &amp;lt; embedding_rank; i++, k++) {
    const int dim = SizeOfDimension(value, i);
    embedding_size *= dim;
    output_shape-&amp;gt;data[k] = dim;
  } 
```&lt;/p&gt;
&lt;p&gt;Both `embedding_size` and `lookup_size` are products of values provided by the user. Hence, a malicious user could trigger overflows in the multiplication.&lt;/p&gt;
&lt;p&gt;In certain scenarios, this can then result in heap OOB read/write.
  
### Patches
We have patched the issue in GitHub commits [f19be71717c497723ba0cea0379e84f061a75e01](https://github.com/tensorflow/tensorflow/commit/f19be71717c497723ba0cea0379e84f061a75e01), [1de49725a5fc4e48f1a3b902ec3599ee99283043](https://github.com/tensorflow/tensorflow/commit/1de49725a5fc4e48f1a3b902ec3599ee99283043) and [a4e401da71458d253b05e41f28637b65baf64be4](https://github.com/tensorflow/tensorflow/commit/a4e401da71458d253b05e41f28637b65baf64be4).&lt;/p&gt;
&lt;p&gt;The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow 2.6.3, and TensorFlow 2.5.3, as these are also…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: tensorflow, PyPI: tensorflow-cpu, PyPI: tensorflow-gpu&lt;/p&gt;
&lt;p&gt;### Impact 
An attacker can craft a TFLite model that would cause an integer overflow [in embedding lookup operations](https://github.com/tensorflow/tensorflow/blob/ca6f96b62ad84207fbec580404eaa7dd7403a550/tensorflow/lite/kernels/embedding_lookup_sparse.cc#L179-L189):&lt;/p&gt;
&lt;p&gt;```cc
  int embedding_size = 1;
  int lookup_size = 1;
  for (int i = 0; i &amp;lt; lookup_rank - 1; i++, k++) {
    const int dim = dense_shape-&amp;gt;data.i32[i];
    lookup_size *= dim;
    output_shape-&amp;gt;data[k] = dim;
  }
  for (int i = 1; i &amp;lt; embedding_rank; i++, k++) {
    const int dim = SizeOfDimension(value, i);
    embedding_size *= dim;
    output_shape-&amp;gt;data[k] = dim;
  } 
```&lt;/p&gt;
&lt;p&gt;Both `embedding_size` and `lookup_size` are products of values provided by the user. Hence, a malicious user could trigger overflows in the multiplication.&lt;/p&gt;
&lt;p&gt;In certain scenarios, this can then result in heap OOB read/write.
  
### Patches
We have patched the issue in GitHub commits [f19be71717c497723ba0cea0379e84f061a75e01](https://github.com/tensorflow/tensorflow/commit/f19be71717c497723ba0cea0379e84f061a75e01), [1de49725a5fc4e48f1a3b902ec3599ee99283043](https://github.com/tensorflow/tensorflow/commit/1de49725a5fc4e48f1a3b902ec3599ee99283043) and [a4e401da71458d253b05e41f28637b65baf64be4](https://github.com/tensorflow/tensorflow/commit/a4e401da71458d253b05e41f28637b65baf64be4).&lt;/p&gt;
&lt;p&gt;The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow 2.6.3, and TensorFlow 2.5.3, as these are also…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-98p5-x8x4-c9m5</guid>
    </item>
  </channel>
</rss>
