Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-55559

Опубликовано: 25 сент. 2025
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

An issue was discovered TensorFlow v2.18.0. A Denial of Service (DoS) occurs when padding is set to 'valid' in tf.keras.layers.Conv2D.

A flaw was found in TensorFlow. When a model uses tf.keras.layers.Conv2D with padding='valid' and is compiled using XLA, the compiler miscalculates the output shape and ends up with a negative dimension. This causes the process to crash during compilation, leading to a denial of service. The same operation works correctly in eager mode because it checks dimensions dynamically, but under XLA the static shape calculation fails and stops execution.

Отчет

The impact is MODERATE because the flaw only causes a denial of service and cannot be used to access data or execute arbitrary code. It happens during local model compilation when TensorFlow’s XLA tries to compile a Conv2D layer with incompatible input and kernel sizes. The error forces the process to abort, interrupting model training or inference. This requires the ability to run or modify TensorFlow model code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift AI (RHOAI)rhoai/odh-modelmesh-runtime-adapter-rhel8Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-modelmesh-runtime-adapter-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2398198tensorflow: Conv2D with 'valid' padding causes XLA compile crash leading to denial of service

EPSS

Процентиль: 19%
0.00061
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
7 месяцев назад

An issue was discovered TensorFlow v2.18.0. A Denial of Service (DoS) occurs when padding is set to 'valid' in tf.keras.layers.Conv2D.

CVSS3: 7.5
nvd
7 месяцев назад

An issue was discovered TensorFlow v2.18.0. A Denial of Service (DoS) occurs when padding is set to 'valid' in tf.keras.layers.Conv2D.

CVSS3: 7.5
debian
7 месяцев назад

An issue was discovered TensorFlow v2.18.0. A Denial of Service (DoS) ...

CVSS3: 7.5
github
7 месяцев назад

An issue was discovered TensorFlow v2.18.0. A Denial of Service (DoS) occurs when padding is set to 'valid' in tf.keras.layers.Conv2D.

CVSS3: 7.5
fstec
больше 1 года назад

Уязвимость функции tf.keras.layers.Conv2D() системы машинного обучения TensorFlow, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 19%
0.00061
Низкий

6.5 Medium

CVSS3