CVE-2020-15192Medium· 4.3▾ SunlitMemory leak in Tensorflow
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.7%
0.7% → 0.8%
If a user passes a list of strings to dlpack.to_dlpack there is a memory leak following an expected validation failure:
https://github.com/tensorflow/tensorflow/blob/0e68f4d3295eb0281a517c3662f6698992b7b2cf/tensorflow/c/eager/dlpack.cc#L100-L104
The allocated memory is from https://github.com/tensorflow/tensorflow/blob/0e68f4d3295eb0281a517c3662f6698992b7b2cf/tensorflow/c/eager/dlpack.cc#L256
The issue occurs because the status argument during validation failures is not properly checked:
https://github.com/tensorflow/tensorflow/blob/0e68f4d3295eb0281a517c3662f6698992b7b2cf/tensorflow/c/eager/dlpack.cc#L265-L267
Since each of the above methods can return an error status, the status value must be checked before continuing.
We have patched the issue in 22e07fb204386768e5bcbea563641ea11f96ceb8 and will release a patch release for all affected versions.
We recommend users to upgrade to TensorFlow 2.2.1 or 2.3.1.
Please consult our security guide for more information regarding the security model and how to contact us with issues and questions.
This vulnerability has been discovered during variant analysis of GHSA-rjjg-hgv6-h69v.
tensorflow >= 2.2.0, < 2.2.1tensorflow >= 2.3.0, < 2.3.1tensorflow-cpu >= 2.2.0, < 2.2.1tensorflow-cpu >= 2.3.0, < 2.3.1tensorflow-gpu >= 2.2.0, < 2.2.1tensorflow-gpu >= 2.3.0, < 2.3.1Upgrade to a patched release:
tensorflow 2.2.1tensorflow 2.3.1tensorflow-cpu 2.2.1tensorflow-cpu 2.3.1tensorflow-gpu 2.2.1tensorflow-gpu 2.3.1Connected by shared product, vendor, weakness, or advisory.
CVE-2020-15207High· 8.7Segfault and data corruption in tensorflow-lite
CVE-2020-15203High· 7.5Denial of Service in Tensorflow
CVE-2020-15210Medium· 6.5Segmentation fault in tensorflow-lite
CVE-2020-15206Critical· 9.0Denial of Service in Tensorflow
CVE-2020-15193High· 7.1Memory corruption in Tensorflow
CVE-2020-15209Medium· 5.9Null pointer dereference in tensorflow-lite