Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pqhm-4wvf-2jg8

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.5

Описание

Missing validation results in undefined behavior in QuantizedConv2D

Impact

The implementation of tf.raw_ops.QuantizedConv2D does not fully validate the input arguments:

import tensorflow as tf input = tf.constant(1, shape=[1, 2, 3, 3], dtype=tf.quint8) filter = tf.constant(1, shape=[1, 2, 3, 3], dtype=tf.quint8) # bad args min_input = tf.constant([], shape=[0], dtype=tf.float32) max_input = tf.constant(0, shape=[], dtype=tf.float32) min_filter = tf.constant(0, shape=[], dtype=tf.float32) max_filter = tf.constant(0, shape=[], dtype=tf.float32) tf.raw_ops.QuantizedConv2D( input=input, filter=filter, min_input=min_input, max_input=max_input, min_filter=min_filter, max_filter=max_filter, strides=[1, 1, 1, 1], padding="SAME")

In this case, references get bound to nullptr for each argument that is empty (in the example, all arguments in the bad args section).

Patches

We have patched the issue in GitHub commit 0f0b080ecde4d3dfec158d6f60da34d5e31693c4.

The fix will be included in TensorFlow 2.9.0. We will also cherrypick this commit on TensorFlow 2.8.1, TensorFlow 2.7.2, and TensorFlow 2.6.4, as these are also affected and still in supported range.

For more information

Please consult our security guide for more information regarding the security model and how to contact us with issues and questions.

Attribution

This vulnerability has been reported by Neophytos Christou from Secure Systems Lab at Brown University.

Пакеты

Наименование

tensorflow

pip
Затронутые версииВерсия исправления

< 2.6.4

2.6.4

Наименование

tensorflow

pip
Затронутые версииВерсия исправления

>= 2.7.0, < 2.7.2

2.7.2

Наименование

tensorflow

pip
Затронутые версииВерсия исправления

>= 2.8.0, < 2.8.1

2.8.1

Наименование

tensorflow-cpu

pip
Затронутые версииВерсия исправления

< 2.6.4

2.6.4

Наименование

tensorflow-cpu

pip
Затронутые версииВерсия исправления

>= 2.7.0, < 2.7.2

2.7.2

Наименование

tensorflow-cpu

pip
Затронутые версииВерсия исправления

>= 2.8.0, < 2.8.1

2.8.1

Наименование

tensorflow-gpu

pip
Затронутые версииВерсия исправления

< 2.6.4

2.6.4

Наименование

tensorflow-gpu

pip
Затронутые версииВерсия исправления

>= 2.7.0, < 2.7.2

2.7.2

Наименование

tensorflow-gpu

pip
Затронутые версииВерсия исправления

>= 2.8.0, < 2.8.1

2.8.1

EPSS

Процентиль: 13%
0.00044
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-20
CWE-476

Связанные уязвимости

CVSS3: 5.5
nvd
больше 3 лет назад

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.QuantizedConv2D` does not fully validate the input arguments. In this case, references get bound to `nullptr` for each argument that is empty. Versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4 contain a patch for this issue.

CVSS3: 5.5
debian
больше 3 лет назад

TensorFlow is an open source platform for machine learning. Prior to v ...

EPSS

Процентиль: 13%
0.00044
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-20
CWE-476