SCA: security update for tensorflow, tensorflow-cpu, tensorflow-gpu (GHSA-79h2-q768-fpxr)

high Tenable Cloud Security Plugin ID 411964

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- TensorFlow is an open source platform for machine learning. When converting transposed convolutions using
per-channel weight quantization the converter segfaults and crashes the Python process. We have patched
the issue in GitHub commit aa0b852a4588cea4d36b74feb05d93055540b450. The fix will be included in
TensorFlow 2.10.0. We will also cherrypick this commit on TensorFlow 2.9.1, TensorFlow 2.8.1, and
TensorFlow 2.7.2, as these are also affected and still in supported range. There are no known workarounds
for this issue. (CVE-2022-36027)

See Also

https://github.com/advisories/GHSA-79h2-q768-fpxr

Plugin Details

Severity: High

ID: 411964

Version: Revision 1.5

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 6/1/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2022-36027

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/16/2022

Vulnerability Publication Date: 9/16/2022

Reference Information

CVE: CVE-2022-36027

cwe: CWE-20