CVE-2022-29204

Missing validation causes denial of service in TensorFlow via `Conv3DBackpropFilterV2`

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.UnsortedSegmentJoin` does not fully validate the input arguments. This results in a `CHECK`-failure which can be used to trigger a denial of service attack. The code assumes `num_segments` is a positive scalar but there is no validation. Since this value is used to allocate the output tensor, a negative value would result in a `CHECK`-failure (assertion failure), as per TFSA-2021-198. Versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4 contain a patch for this issue.


We have discovered 59 live websites that are affected by CVE-2022-29204.

Run a Free Instant Scan




Affected Software

Product  tensorflow
Category JavaScript Libraries
Vulnerable Domains59 live websites (100% of tensorflow install base)
Vulnerable Versions
  • from 0 through 2.6.4
  • from 2.7 through 2.7.2
  • from 2.8 through 2.8.1
  • from 2.9 through 2.9
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-191 Integer Underflow (Wrap or Wraparound)



Details

  • Published - May 20, 2022
  • Updated - Apr 22, 2025

Website Distribution by Country

Number of websites using CVE-2022-29204
United States43 websites



Germany4 websites
India2 websites
Netherlands2 websites
Austria1 websites
Canada1 websites
Chile1 websites
Cyprus1 websites
Denmark1 websites
GB1 websites

Website Distribution by TLD

Number of websites using CVE-2022-29204
.com28 websites
.io2 websites
.org2 websites
.at1 websites
.ch1 websites
.de1 websites
.dk1 websites
.net1 websites

Websites affected by CVE-2022-29204

Top websites that are affected by CVE-2022-29204. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.com United States***,***
*******.************.de Germany***,***
******.me United States*,***,***
***********.com United States*,***,***
************.com United States*,***,***
***********.com United States*,***,***
*******.**.kr Korea, South*,***,***
**********.com Netherlands*,***,***
*********.******.**********.org Germany*,***,***
***********.com United States*,***,***
See full domain list

FAQ

CVE-2022-29204 is Integer Underflow (Wrap or Wraparound) in tensorflow
A total of 59 websites have been identified as vulnerable to CVE-2022-29204, based on global website indexing conducted by WebTechSurvey.
The tensorflow is affected by the CVE-2022-29204 vulnerability.
tensorflow versions up to 2.9 are vulnerable to CVE-2022-29204.
CVE-2022-29204 is resolved in version 2.9 of tensorflow.

References