Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8wwm-6264-x792

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.5

Описание

Core dump when loading TFLite models with quantization in TensorFlow

Impact

Certain TFLite models that were created using TFLite model converter would crash when loaded in the TFLite interpreter. The culprit is that during quantization the scale of values could be greater than 1 but code was always assuming sub-unit scaling.

Thus, since code was calling QuantizeMultiplierSmallerThanOneExp, the TFLITE_CHECK_LT assertion would trigger and abort the process.

Patches

We have patched the issue in GitHub commit a989426ee1346693cc015792f11d715f6944f2b8.

The fix will be included in TensorFlow 2.9.0. We will also cherrypick this commit on TensorFlow 2.8.1, TensorFlow 2.7.2, and TensorFlow 2.6.4, as these are also affected and still in supported range.

For more information

Please consult our security guide for more information regarding the security model and how to contact us with issues and questions.

Attribution

This vulnerability has been reported externally via a GitHub issue.

Пакеты

Наименование

tensorflow

pip
Затронутые версииВерсия исправления

< 2.6.4

2.6.4

Наименование

tensorflow

pip
Затронутые версииВерсия исправления

>= 2.7.0, < 2.7.2

2.7.2

Наименование

tensorflow

pip
Затронутые версииВерсия исправления

>= 2.8.0, < 2.8.1

2.8.1

Наименование

tensorflow-cpu

pip
Затронутые версииВерсия исправления

< 2.6.4

2.6.4

Наименование

tensorflow-cpu

pip
Затронутые версииВерсия исправления

>= 2.7.0, < 2.7.2

2.7.2

Наименование

tensorflow-cpu

pip
Затронутые версииВерсия исправления

>= 2.8.0, < 2.8.1

2.8.1

Наименование

tensorflow-gpu

pip
Затронутые версииВерсия исправления

< 2.6.4

2.6.4

Наименование

tensorflow-gpu

pip
Затронутые версииВерсия исправления

>= 2.7.0, < 2.7.2

2.7.2

Наименование

tensorflow-gpu

pip
Затронутые версииВерсия исправления

>= 2.8.0, < 2.8.1

2.8.1

EPSS

Процентиль: 25%
0.00084
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.5
nvd
больше 3 лет назад

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, certain TFLite models that were created using TFLite model converter would crash when loaded in the TFLite interpreter. The culprit is that during quantization the scale of values could be greater than 1 but code was always assuming sub-unit scaling. Thus, since code was calling `QuantizeMultiplierSmallerThanOneExp`, the `TFLITE_CHECK_LT` assertion would trigger and abort the process. Versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4 contain a patch for this issue.

CVSS3: 5.5
debian
больше 3 лет назад

TensorFlow is an open source platform for machine learning. Prior to v ...

EPSS

Процентиль: 25%
0.00084
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-20