PT-2023-26542 · Unknown · Paddlepaddle

Tong Liu

·

Published

2023-07-26

·

Updated

2023-07-31

·

CVE-2023-38669

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PaddlePaddle versions prior to 2.5.0
Description The issue is related to a use after free condition in the paddle.diagonal function. This resulted in a potentially exploitable condition.
Recommendations For versions prior to 2.5.0, update to version 2.5.0 or later to resolve the issue.

Exploit

Fix

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2023-38669
GHSA-8WFH-QXXV-3Q8C
PYSEC-2023-122

Affected Products

Paddlepaddle