Input validation error in TensorFlow - CVE-2020-15210

 

Input validation error in TensorFlow - CVE-2020-15210

Published: September 25, 2020 / Updated: October 2, 2020


Vulnerability identifier: #VU47282
CSH Severity: Medium
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-15210
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to damange or delete data.

In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, if a TFLite saved model uses the same tensor as both input and output of an operator, then, depending on the operator, we can observe a segmentation fault or just memory corruption. We have patched the issue in d58c96946b and will release patch releases for all versions between 1.15 and 2.3. We recommend users to upgrade to TensorFlow 1.15.4, 2.0.3, 2.1.2, 2.2.1, or 2.3.1.


Affected software

TensorFlow

How to mitigate CVE-2020-15210

Install update from vendor's website.

TensorFlow - addressed in versions 1.15.4, 2.0.3, 2.1.2, 2.2.1, 2.3.1

External References

Related Security Bulletins