PT-2022-3914 · Apache · Apache Mxnet

Dwi Siswanto

·

Published

2022-07-24

·

Updated

2023-11-06

·

CVE-2022-24294

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache MXNet versions prior to 1.9.1
Description A regular expression used in Apache MXNet is vulnerable to a potential denial-of-service by excessive resource consumption. The issue could be exploited when loading a model in Apache MXNet that has a specially crafted operator name, causing the regular expression evaluation to use excessive resources to attempt a match.
Recommendations For Apache MXNet versions prior to 1.9.1, update to version 1.9.1 or later to resolve the issue. As a temporary workaround, consider restricting the loading of models with specially crafted operator names to minimize the risk of exploitation.

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2022-04732
BIT-MXNET-2022-24294
CVE-2022-24294
GHSA-XXJ3-55P6-XG3H

Affected Products

Apache Mxnet