CVE-2020-15193High· 7.1▾ TwilightMemory corruption in Tensorflow
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.7%
0.7% → 0.8%
The implementation of dlpack.to_dlpack can be made to use uninitialized memory resulting in further memory corruption. This is because the pybind11 glue code assumes that the argument is a tensor:
https://github.com/tensorflow/tensorflow/blob/0e68f4d3295eb0281a517c3662f6698992b7b2cf/tensorflow/python/tfe_wrapper.cc#L1361
However, there is nothing stopping users from passing in a Python object instead of a tensor.
In [2]: tf.experimental.dlpack.to_dlpack([2])
==1720623==WARNING: MemorySanitizer: use-of-uninitialized-value
#0 0x55b0ba5c410a in tensorflow::(anonymous namespace)::GetTensorFromHandle(TFE_TensorHandle*, TF_Status*) third_party/tensorflow/c/eager/dlpack.cc:46:7
#1 0x55b0ba5c38f4 in tensorflow::TFE_HandleToDLPack(TFE_TensorHandle*, TF_Status*) third_party/tensorflow/c/eager/dlpack.cc:252:26
...
The uninitialized memory address is due to a reinterpret_cast
https://github.com/tensorflow/tensorflow/blob/0e68f4d3295eb0281a517c3662f6698992b7b2cf/tensorflow/python/eager/pywrap_tensor.cc#L848-L850
Since the PyObject is a Python object, not a TensorFlow Tensor, the cast to EagerTensor fails.
We have patched the issue in 22e07fb204386768e5bcbea563641ea11f96ceb8 and will release a patch release for all affected versions.
We recommend users to upgrade to TensorFlow 2.2.1 or 2.3.1.
Please consult our security guide for more information regarding the security model and how to contact us with issues and questions.
This vulnerability has been reported by members of the Aivul Team from Qihoo 360.
tensorflow >= 2.2.0, < 2.2.1tensorflow >= 2.3.0, < 2.3.1tensorflow-cpu >= 2.2.0, < 2.2.1tensorflow-cpu >= 2.3.0, < 2.3.1tensorflow-gpu >= 2.2.0, < 2.2.1tensorflow-gpu >= 2.3.0, < 2.3.1Upgrade to a patched release:
tensorflow 2.2.1tensorflow 2.3.1tensorflow-cpu 2.2.1tensorflow-cpu 2.3.1tensorflow-gpu 2.2.1tensorflow-gpu 2.3.1Connected by shared product, vendor, weakness, or advisory.
CVE-2020-15207High· 8.7Segfault and data corruption in tensorflow-lite
CVE-2020-15203High· 7.5Denial of Service in Tensorflow
CVE-2020-15210Medium· 6.5Segmentation fault in tensorflow-lite
CVE-2020-15206Critical· 9.0Denial of Service in Tensorflow
CVE-2020-15209Medium· 5.9Null pointer dereference in tensorflow-lite
CVE-2020-15191Medium· 5.3Undefined behavior in Tensorflow