PT-2022-3914 · Apache · Apache Mxnet
Dwi Siswanto
·
Published
2022-07-24
·
Updated
2023-11-06
·
CVE-2022-24294
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache MXNet versions prior to 1.9.1
Description
A regular expression used in Apache MXNet is vulnerable to a potential denial-of-service by excessive resource consumption. The issue could be exploited when loading a model in Apache MXNet that has a specially crafted operator name, causing the regular expression evaluation to use excessive resources to attempt a match.
Recommendations
For Apache MXNet versions prior to 1.9.1, update to version 1.9.1 or later to resolve the issue. As a temporary workaround, consider restricting the loading of models with specially crafted operator names to minimize the risk of exploitation.
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Mxnet