Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-27j5-4p9v-pp67

Опубликовано: 25 авг. 2021
Источник: github
Github: Прошло ревью
CVSS4: 5.7
CVSS3: 5.5

Описание

std::abort raised from TensorListReserve

Impact

Providing a negative element to num_elements list argument of tf.raw_ops.TensorListReserve causes the runtime to abort the process due to reallocating a std::vector to have a negative number of elements:

import tensorflow as tf tf.raw_ops.TensorListReserve( element_shape = tf.constant([1]), num_elements=tf.constant([-1]), element_dtype = tf.int32)

The implementation calls std::vector.resize() with the new size controlled by input given by the user, without checking that this input is valid.

Patches

We have patched the issue in GitHub commit 8a6e874437670045e6c7dc6154c7412b4a2135e2.

The fix will be included in TensorFlow 2.6.0. We will also cherrypick this commit on TensorFlow 2.5.1, TensorFlow 2.4.3, and TensorFlow 2.3.4, as these are also affected and still in supported range.

For more information

Please consult our security guide for more information regarding the security model and how to contact us with issues and questions.

Attribution

This vulnerability has been reported by members of the Aivul Team from Qihoo 360.

Пакеты

Наименование

tensorflow

pip
Затронутые версииВерсия исправления

< 2.3.4

2.3.4

Наименование

tensorflow

pip
Затронутые версииВерсия исправления

>= 2.4.0, < 2.4.3

2.4.3

Наименование

tensorflow

pip
Затронутые версииВерсия исправления

= 2.5.0

2.5.1

Наименование

tensorflow-cpu

pip
Затронутые версииВерсия исправления

< 2.3.4

2.3.4

Наименование

tensorflow-cpu

pip
Затронутые версииВерсия исправления

>= 2.4.0, < 2.4.3

2.4.3

Наименование

tensorflow-cpu

pip
Затронутые версииВерсия исправления

= 2.5.0

2.5.1

Наименование

tensorflow-gpu

pip
Затронутые версииВерсия исправления

< 2.3.4

2.3.4

Наименование

tensorflow-gpu

pip
Затронутые версииВерсия исправления

>= 2.4.0, < 2.4.3

2.4.3

Наименование

tensorflow-gpu

pip
Затронутые версииВерсия исправления

= 2.5.0

2.5.1

EPSS

Процентиль: 1%
0.00012
Низкий

5.7 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-617

Связанные уязвимости

CVSS3: 5.5
nvd
почти 4 года назад

TensorFlow is an end-to-end open source platform for machine learning. In affected versions providing a negative element to `num_elements` list argument of `tf.raw_ops.TensorListReserve` causes the runtime to abort the process due to reallocating a `std::vector` to have a negative number of elements. The [implementation](https://github.com/tensorflow/tensorflow/blob/8d72537c6abf5a44103b57b9c2e22c14f5f49698/tensorflow/core/kernels/list_kernels.cc#L312) calls `std::vector.resize()` with the new size controlled by input given by the user, without checking that this input is valid. We have patched the issue in GitHub commit 8a6e874437670045e6c7dc6154c7412b4a2135e2. The fix will be included in TensorFlow 2.6.0. We will also cherrypick this commit on TensorFlow 2.5.1, TensorFlow 2.4.3, and TensorFlow 2.3.4, as these are also affected and still in supported range.

CVSS3: 5.5
debian
почти 4 года назад

TensorFlow is an end-to-end open source platform for machine learning. ...

suse-cvrf
около 3 лет назад

Security update for tensorflow2

EPSS

Процентиль: 1%
0.00012
Низкий

5.7 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-617