Google · Tensorflow · CVE-2020-15206
**Name of the Vulnerable Software and Affected Versions**
TensorFlow versions prior to 1.15.4
TensorFlow versions prior to 2.0.3
TensorFlow versions prior to 2.1.2
TensorFlow versions prior to 2.2.1
TensorFlow versions prior to 2.3.1
**Description**
Changing the TensorFlow's `SavedModel` protocol buffer and altering the name of required keys results in segfaults and data corruption while loading the model. This can cause a denial of service in products using `tensorflow-serving` or other inference-as-a-service installments.
**Recommendations**
Upgrade to TensorFlow 1.15.4
Upgrade to TensorFlow 2.0.3
Upgrade to TensorFlow 2.1.2
Upgrade to TensorFlow 2.2.1
Upgrade to TensorFlow 2.3.1