#VU49328 Input validation error in TensorFlow - CVE-2020-26270
Published: December 11, 2020 / Updated: January 7, 2021
TensorFlow
TensorFlow
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation when processing an input with zero-length within the the LSTM/GRU layer. A local user can pass specially crafted input to the application and perform a denial of service (DoS) attack.
The vulnerability affects TensorFlow running an LSTM/GRU model.
Remediation
External links
- https://github.com/tensorflow/tensorflow/commit/14755416e364f17fb1870882fa778c7fec7f16e3
- https://github.com/tensorflow/tensorflow/security/advisories/GHSA-m648-33qf-v3gp
- https://github.com/tensorflow/tensorflow/releases/tag/v2.3.2
- https://github.com/tensorflow/tensorflow/releases/tag/v2.2.2
- https://github.com/tensorflow/tensorflow/releases/tag/v2.1.3
- https://github.com/tensorflow/tensorflow/releases/tag/v2.0.4
- https://github.com/tensorflow/tensorflow/releases/tag/v1.15.5