PT-2024-14511 · Unknown · Paddlepaddle

Tong Liu

·

Published

2024-01-03

·

Updated

2024-01-05

·

CVE-2023-52304

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PaddlePaddle versions prior to 2.6.0
Description The issue is a stack overflow in the paddle.searchsorted function. This flaw can lead to a denial of service or potentially more severe consequences.
Recommendations For versions prior to 2.6.0, update to version 2.6.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the paddle.searchsorted function until a patch is available.

Fix

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2023-52304
GHSA-4RRV-8GCP-24V8
PYSEC-2024-136

Affected Products

Paddlepaddle