TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of tf.raw_ops.QuantizeAndDequantizeV4Grad does not fully validate the input arguments. This results in a CHECK-failure which can be used to trigger a denial of service attack. Versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4 contain a patch for this issue.
{
"cwe_ids": [
"CWE-20"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/29xxx/CVE-2022-29192.json",
"cna_assigner": "GitHub_M"
}{
"cpe": [
"cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:*",
"cpe:2.3:a:google:tensorflow:2.9.0:rc0:*:*:*:*:*:*",
"cpe:2.3:a:google:tensorflow:2.9.0:rc1:*:*:*:*:*:*",
"cpe:2.3:a:google:tensorflow:2.9.0:rc2:*:*:*:*:*:*"
],
"source": [
"CPE_RANGE",
"CPE_STRING",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.6.4"
},
{
"introduced": "2.7.0"
},
{
"fixed": "2.7.2"
},
{
"introduced": "2.8.0"
},
{
"fixed": "2.8.1"
},
{
"introduced": "2.9.0-rc0"
},
{
"last_affected": "2.9.0-rc0"
},
{
"introduced": "2.9.0-rc1"
},
{
"last_affected": "2.9.0-rc1"
},
{
"introduced": "2.9.0-rc2"
},
{
"last_affected": "2.9.0-rc2"
}
]
}"2026-07-22T02:24:34Z"
[
{
"signature_type": "Line",
"target": {
"file": "tensorflow/core/kernels/quantize_and_dequantize_op.cc"
},
"deprecated": false,
"source": "https://github.com/tensorflow/tensorflow/commit/098e7762d909bac47ce1dbabe6dfd06294cb9d58",
"id": "CVE-2022-29192-78e09098",
"signature_version": "v1",
"digest": {
"line_hashes": [
"120981903310890843462815705631920945426",
"292421236963177889138276403529288917321",
"42238368156265540577234145199898733255",
"305968661291598397075283599953005703740",
"141389913203323895025341986638092435522",
"61351432838858345100926409355393055148",
"77385433454292442033542472103933357951",
"21969950373092411531080918912167361529",
"251490343838775261567684553050776471889",
"162784155810784569485216084736799950027",
"159158695386339290271310405070460159867",
"156782360959102056704080136926718292446",
"326772452048309788921462803880855422168",
"113070673108413276677113028815828558529"
],
"threshold": 0.9
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-29192.json"