acoustic-carpenter-78188
07/14/2023, 4:31 PMTensorFlow 2.8.1
Release 2.8.1
This releases introduces several vulnerability fixes:
• Fixes a code injection in(CVE-2022-29216)saved_model_cli
• Fixes a missing validation which causesto crash (CVE-2022-29193)TensorSummaryV2
• Fixes a missing validation which crashes(CVE-2022-29192)QuantizeAndDequantizeV4Grad
• Fixes a missing validation which causes denial of service via(CVE-2022-29194)DeleteSessionTensor
• Fixes a missing validation which causes denial of service via(CVE-2022-29191)GetSessionTensor
• Fixes a missing validation which causes denial of service via(CVE-2022-29195)StagePeek
• Fixes a missing validation which causes denial of service via(CVE-2022-29197)UnsortedSegmentJoin
• Fixes a missing validation which causes denial of service via(CVE-2022-29199)LoadAndRemapMatrix
• Fixes a missing validation which causes denial of service via(CVE-2022-29198)SparseTensorToCSRSparseMatrix
• Fixes a missing validation which causes denial of service via(CVE-2022-29200)LSTMBlockCell
• Fixes a missing validation which causes denial of service via(CVE-2022-29196)Conv3DBackpropFilterV2
• Fixes afailure in depthwise ops via overflows (CVE-2021-41197)CHECK
• Fixes issues arising from undefined behavior stemming from users supplying invalid resource handles (CVE-2022-29207)
• Fixes a segfault due to missing support for quantized types (CVE-2022-29205)
• Fixes a missing validation which results in undefined behavior in(CVE-2022-29206)SparseTensorDenseAdd
• Fixes a missing validation which results in undefined behavior in(CVE-2022-29201)QuantizedConv2D
• Fixes an integer overflow in(CVE-2022-29203)SpaceToBatchND
• Fixes a segfault and OOB write due to incomplete validation in(CVE-2022-29208)EditDistance
• Fixes a missing validation which causes denial of service via(CVE-2022-29204)Conv3DBackpropFilterV2
• Fixes a denial of service indue to lack of validation (CVE-2022-29202)tf.ragged.constant
• Fixes a segfault whenis called with NaN values (CVE-2022-29211)tf.histogram_fixed_width
• Fixes a core dump when loading TFLite models with quantization (CVE-2022-29212)
• Fixes crashes stemming from incomplete validation in signal ops (CVE-2022-29213)
• Fixes a type confusion leading to-failure based denial of service (CVE-2022-29209)CHECK
• Fixes a heap buffer overflow due to incorrect hash function (CVE-2022-29210)
• Updatestocurl
to handle (CVE-2022-22576, (CVE-2022-27774, (CVE-2022-27775, (CVE-2022-27776, (CVE-2022-27778, (CVE-2022-27779, (CVE-2022-27780, (CVE-2022-27781, (CVE-2022-27782 and (CVE-2022-301157.83.1
• UpdatesChangelog Sourced from tensorflow's changelog.tozlib
after1.2.12
was pulled due to security issue1.2.11
Release 2.8.1
This releases introduces several vulnerability fixes:
• Fixes a code injection in(CVE-2022-29216)saved_model_cli
• Fixes a missing validation which causesto crash (CVE-2022-29193)TensorSummaryV2
• Fixes a missing validation which crashes(CVE-2022-29192)QuantizeAndDequantizeV4Grad
• Fixes a missing validation which causes denial of service via(CVE-2022-29194)DeleteSessionTensor
• Fixes a missing validation which causes denial of service via(CVE-2022-29191)GetSessionTensor
• Fixes a missing validation which causes denial of service via(CVE-2022-29195)StagePeek
• Fixes a missing validation which causes denial of service via(CVE-2022-29197)UnsortedSegmentJoin
• Fixes a missing validation which causes denial of service via(CVE-2022-29199)LoadAndRemapMatrix
• Fixes a missing validation which causes denial of service via(CVE-2022-29198)SparseTensorToCSRSparseMatrix
• Fixes a missing validation which causes denial of service via(CVE-2022-29200)LSTMBlockCell
• Fixes a missing validation which causes denial of service via(CVE-2022-29196)Conv3DBackpropFilterV2
• Fixes afailure in depthwise ops via overflows (CVE-2021-41197)CHECK
• Fixes issues arising from undefined behavior stemming from users supplying invalid resource handles (CVE-2022-29207)
• Fixes a segfault due to missing support for quantized types (CVE-2022-29205)
• Fixes a missing validation which results in undefined behavior inflyteorg/flytesnacks GitHub Actions: Mark github pre-release as Release GitHub Actions: Publish artifacts to github release GitHub Actions: Create Prerelease GitHub Actions: Bump Version ✅ 26 other checks have passed 26/30 successful checks(<https://cve.mitre.org/cgi-bin/cvename.cgi?name=CV…SparseTensorDenseAdd
acoustic-carpenter-78188
07/14/2023, 4:31 PM