Sourced from tensorflow's releases.
TensorFlow 2.9.3
Release 2.9.3
This release introduces several vulnerability fixes:
- Fixes an overflow in
tf.keras.losses.poisson(CVE-2022-41887)- Fixes a heap OOB failure in
ThreadUnsafeUnigramCandidateSamplercaused by missing validation (CVE-2022-41880)- Fixes a segfault in
ndarray_tensor_bridge(CVE-2022-41884)- Fixes an overflow in
FusedResizeAndPadConv2D(CVE-2022-41885)- Fixes a overflow in
ImageProjectiveTransformV2(CVE-2022-41886)- Fixes an FPE in
tf.image.generate_bounding_box_proposalson GPU (CVE-2022-41888)- Fixes a segfault in
pywrap_tfe_srccaused by invalid attributes (CVE-2022-41889)- Fixes a
CHECKfail inBCast(CVE-2022-41890)- Fixes a segfault in
TensorListConcat(CVE-2022-41891)- Fixes a
CHECK_EQfail inTensorListResize(CVE-2022-41893)- Fixes an overflow in
CONV_3D_TRANSPOSEon TFLite (CVE-2022-41894)- Fixes a heap OOB in
MirrorPadGrad(CVE-2022-41895)- Fixes a crash in
Mfcc(CVE-2022-41896)- Fixes a heap OOB in
FractionalMaxPoolGrad(CVE-2022-41897)- Fixes a
CHECKfail inSparseFillEmptyRowsGrad(CVE-2022-41898)- Fixes a
CHECKfail inSdcaOptimizer(CVE-2022-41899)- Fixes a heap OOB in
FractionalAvgPoolandFractionalMaxPool(CVE-2022-41900)- Fixes a
CHECK_EQinSparseMatrixNNZ(CVE-2022-41901)- Fixes an OOB write in grappler (CVE-2022-41902)
- Fixes a overflow in
ResizeNearestNeighborGrad(CVE-2022-41907)- Fixes a
CHECKfail inPyFunc(CVE-2022-41908)- Fixes a segfault in
CompositeTensorVariantToComponents(CVE-2022-41909)- Fixes a invalid char to bool conversion in printing a tensor (CVE-2022-41911)
- Fixes a heap overflow in
QuantizeAndDequantizeV2(CVE-2022-41910)- Fixes a
CHECKfailure inSobolSamplevia missing validation (CVE-2022-35935)- Fixes a
CHECKfail inTensorListScatterandTensorListScatterV2in eager mode (CVE-2022-35935)TensorFlow 2.9.2
Release 2.9.2
This releases introduces several vulnerability fixes:
- Fixes a
CHECKfailure in tf.reshape caused by overflows (CVE-2022-35934)- Fixes a
CHECKfailure inSobolSamplecaused by missing validation (CVE-2022-35935)- Fixes an OOB read in
Gather_ndop in TF Lite (CVE-2022-35937)- Fixes a
CHECKfailure inTensorListReservecaused by missing validation (CVE-2022-35960)- Fixes an OOB write in
Scatter_ndop in TF Lite (CVE-2022-35939)- Fixes an integer overflow in
RaggedRangeOp(CVE-2022-35940)- Fixes a
CHECKfailure inAvgPoolOp(CVE-2022-35941)- Fixes a
CHECKfailures inUnbatchGradOp(CVE-2022-35952)- Fixes a segfault TFLite converter on per-channel quantized transposed convolutions (CVE-2022-36027)
- Fixes a
CHECKfailures inAvgPool3DGrad(CVE-2022-35959)- Fixes a
CHECKfailures inFractionalAvgPoolGrad(CVE-2022-35963)- Fixes a segfault in
BlockLSTMGradV2(CVE-2022-35964)- Fixes a segfault in
LowerBoundandUpperBound(CVE-2022-35965)
... (truncated)
Sourced from tensorflow's changelog.
Release 2.9.3
This release introduces several vulnerability fixes:
- Fixes an overflow in
tf.keras.losses.poisson(CVE-2022-41887)- Fixes a heap OOB failure in
ThreadUnsafeUnigramCandidateSamplercaused by missing validation (CVE-2022-41880)- Fixes a segfault in
ndarray_tensor_bridge(CVE-2022-41884)- Fixes an overflow in
FusedResizeAndPadConv2D(CVE-2022-41885)- Fixes a overflow in
ImageProjectiveTransformV2(CVE-2022-41886)- Fixes an FPE in
tf.image.generate_bounding_box_proposalson GPU (CVE-2022-41888)- Fixes a segfault in
pywrap_tfe_srccaused by invalid attributes (CVE-2022-41889)- Fixes a
CHECKfail inBCast(CVE-2022-41890)- Fixes a segfault in
TensorListConcat(CVE-2022-41891)- Fixes a
CHECK_EQfail inTensorListResize(CVE-2022-41893)- Fixes an overflow in
CONV_3D_TRANSPOSEon TFLite (CVE-2022-41894)- Fixes a heap OOB in
MirrorPadGrad(CVE-2022-41895)- Fixes a crash in
Mfcc(CVE-2022-41896)- Fixes a heap OOB in
FractionalMaxPoolGrad(CVE-2022-41897)- Fixes a
CHECKfail inSparseFillEmptyRowsGrad(CVE-2022-41898)- Fixes a
CHECKfail inSdcaOptimizer(CVE-2022-41899)- Fixes a heap OOB in
FractionalAvgPoolandFractionalMaxPool(CVE-2022-41900)- Fixes a
CHECK_EQinSparseMatrixNNZ(CVE-2022-41901)- Fixes an OOB write in grappler (CVE-2022-41902)
- Fixes a overflow in
ResizeNearestNeighborGrad(CVE-2022-41907)- Fixes a
CHECKfail inPyFunc(CVE-2022-41908)- Fixes a segfault in
CompositeTensorVariantToComponents(CVE-2022-41909)- Fixes a invalid char to bool conversion in printing a tensor (CVE-2022-41911)
- Fixes a heap overflow in
QuantizeAndDequantizeV2(CVE-2022-41910)- Fixes a
CHECKfailure inSobolSamplevia missing validation (CVE-2022-35935)- Fixes a
CHECKfail inTensorListScatterandTensorListScatterV2in eager mode (CVE-2022-35935)Release 2.8.4
This release introduces several vulnerability fixes:
- Fixes a heap OOB failure in
ThreadUnsafeUnigramCandidateSamplercaused by missing validation (CVE-2022-41880)- Fixes a segfault in
ndarray_tensor_bridge(CVE-2022-41884)- Fixes an overflow in
FusedResizeAndPadConv2D(CVE-2022-41885)- Fixes a overflow in
ImageProjectiveTransformV2(CVE-2022-41886)- Fixes an FPE in
tf.image.generate_bounding_box_proposalson GPU (CVE-2022-41888)- Fixes a segfault in
pywrap_tfe_srccaused by invalid attributes (CVE-2022-41889)- Fixes a
CHECKfail inBCast(CVE-2022-41890)- Fixes a segfault in
TensorListConcat(CVE-2022-41891)- Fixes a
CHECK_EQfail inTensorListResize(CVE-2022-41893)- Fixes an overflow in
CONV_3D_TRANSPOSEon TFLite (CVE-2022-41894)- Fixes a heap OOB in
MirrorPadGrad(CVE-2022-41895)- Fixes a crash in
Mfcc(CVE-2022-41896)- Fixes a heap OOB in
FractionalMaxPoolGrad(CVE-2022-41897)- Fixes a
CHECKfail inSparseFillEmptyRowsGrad(CVE-2022-41898)- Fixes a
CHECKfail inSdcaOptimizer(CVE-2022-41899)
... (truncated)
a5ed5f3
Merge pull request #58584
from tensorflow/vinila21-patch-2258f9a1
Update py_func.cccd27cfb
Merge pull request #58580
from tensorflow-jenkins/version-numbers-2.9.3-244743e75385
Update version numbers to 2.9.3bc72c39
Merge pull request #58482
from tensorflow-jenkins/relnotes-2.9.3-256953506c90
Update RELEASE.md8dcb48e
Update RELEASE.md4f34ec8
Merge pull request #58576
from pak-laura/c2.99f03a9d3bafe902c1e6beb105b2f2417...6fc67e4
Replace CHECK with returning an InternalError on failing to create
python tuple5dbe90a
Merge pull request #58570
from tensorflow/r2.9-7b174a0f2e4