CVE-2022-41907

Overflow in `ResizeNearestNeighborGrad` in Tensorflow

TensorFlow is an open source platform for machine learning. When `tf.raw_ops.ResizeNearestNeighborGrad` is given a large `size` input, it overflows. We have patched the issue in GitHub commit 00c821af032ba9e5f5fa3fe14690c8d28a657624. The fix will be included in TensorFlow 2.11. We will also cherrypick this commit on TensorFlow 2.10.1, 2.9.3, and TensorFlow 2.8.4, as these are also affected and still in supported range.


We have discovered 27 live websites that are affected by CVE-2022-41907.

Run a Free Instant Scan




Affected Software

Product  tensorflow
Category JavaScript Libraries
Vulnerable Domains27 live websites (7.54% of tensorflow install base)
Vulnerable Versions
  • from 0 through 2.8.4
  • from 2.9 through 2.9.3
  • from 2.10 through 2.10.1
Vulnerable Versions Count5 versions ( 71% of all versions)


Common Weakness Enumeration

CWE-131 Incorrect Calculation of Buffer Size



Details

  • Published - Nov 18, 2022
  • Updated - Apr 22, 2025

Website Distribution by Country

Number of websites using CVE-2022-41907
United States19 websites



Germany2 websites
India2 websites
Brazil1 websites
Canada1 websites
Korea, South1 websites
Netherlands1 websites

Website Distribution by TLD

Number of websites using CVE-2022-41907
.com15 websites
.net2 websites
.com.br1 websites
.io1 websites
.org1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2022-41907

Top websites that are affected by CVE-2022-41907. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.com United States***,***
************.com United States***,***
******.me United States*,***,***
***********.com United States*,***,***
************.com United States*,***,***
****.net United States*,***,***
***********.com United States*,***,***
*******.**.kr Korea, South*,***,***
**********.com Netherlands*,***,***
********.app United States*,***,***
See full domain list

FAQ

CVE-2022-41907 is Incorrect Calculation of Buffer Size in tensorflow
A total of 27 websites have been identified as vulnerable to CVE-2022-41907, based on global website indexing conducted by WebTechSurvey.
The tensorflow is affected by the CVE-2022-41907 vulnerability.
tensorflow versions up to 2.10.1 are vulnerable to CVE-2022-41907.
CVE-2022-41907 is resolved in version 2.10.1 of tensorflow.