PT-2020-16390 · Google · Tensorflow

Published

2020-12-10

·

Updated

2024-03-06

·

CVE-2020-26267

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TensorFlow versions prior to 1.15.5 TensorFlow versions prior to 2.0.4 TensorFlow versions prior to 2.1.3 TensorFlow versions prior to 2.2.2 TensorFlow versions prior to 2.3.2 TensorFlow versions prior to 2.4.0
Description The tf.raw ops.DataFormatVecPermute API does not validate the src format and dst format attributes, assuming they define a permutation of NHWC. This can result in uninitialized memory accesses, read outside of bounds, and even crashes. The issue is similar for tf.raw ops.DataFormatDimMap.
Recommendations For versions prior to 1.15.5, update to version 1.15.5 or later. For versions prior to 2.0.4, update to version 2.0.4 or later. For versions prior to 2.1.3, update to version 2.1.3 or later. For versions prior to 2.2.2, update to version 2.2.2 or later. For versions prior to 2.3.2, update to version 2.3.2 or later. For versions prior to 2.4.0, update to version 2.4.0 or later.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

BIT-TENSORFLOW-2020-26267
CVE-2020-26267
GHSA-C9F3-9WFR-WGH7
OPENSUSE-SU-2022:10014-1
PYSEC-2020-140
PYSEC-2020-298
PYSEC-2020-333

Affected Products

Tensorflow