CVE-2020-15195High· 8.5▾ TwilightHeap buffer overflow in Tensorflow
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 46.8 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.9%
0.9% → 0.9%
The implementation of SparseFillEmptyRowsGrad uses a double indexing pattern:
https://github.com/tensorflow/tensorflow/blob/0e68f4d3295eb0281a517c3662f6698992b7b2cf/tensorflow/core/kernels/sparse_fill_empty_rows_op.cc#L263-L269
It is possible for reverse_index_map(i) to be an index outside of bounds of grad_values, thus resulting in a heap buffer overflow.
We have patched the issue in 390611e0d45c5793c7066110af37c8514e6a6c54 and will release a patch release for all affected versions.
We recommend users to upgrade to TensorFlow 1.15.4, 2.0.3, 2.1.2, 2.2.1, or 2.3.1.
Please consult our security guide for more information regarding the security model and how to contact us with issues and questions.
This vulnerability has been reported by members of the Aivul Team from Qihoo 360.
tensorflow < 1.15.4tensorflow >= 2.0.0, < 2.0.3tensorflow >= 2.1.0, < 2.1.2tensorflow >= 2.2.0, < 2.2.1tensorflow >= 2.3.0, < 2.3.1tensorflow-cpu < 1.15.4tensorflow-cpu >= 2.0.0, < 2.0.3tensorflow-cpu >= 2.1.0, < 2.1.2tensorflow-cpu >= 2.2.0, < 2.2.1tensorflow-cpu >= 2.3.0, < 2.3.1tensorflow-gpu < 1.15.4tensorflow-gpu >= 2.0.0, < 2.0.3tensorflow-gpu >= 2.1.0, < 2.1.2tensorflow-gpu >= 2.2.0, < 2.2.1tensorflow-gpu >= 2.3.0, < 2.3.1Upgrade to a patched release:
tensorflow 1.15.4tensorflow 2.0.3tensorflow 2.1.2tensorflow 2.2.1tensorflow 2.3.1tensorflow-cpu 1.15.4tensorflow-cpu 2.0.3tensorflow-cpu 2.1.2tensorflow-cpu 2.2.1tensorflow-cpu 2.3.1tensorflow-gpu 1.15.4tensorflow-gpu 2.0.3tensorflow-gpu 2.1.2tensorflow-gpu 2.2.1tensorflow-gpu 2.3.1Connected by shared product, vendor, weakness, or advisory.
CVE-2020-15207High· 8.7Segfault and data corruption in tensorflow-lite
CVE-2020-15203High· 7.5Denial of Service in Tensorflow
CVE-2020-15210Medium· 6.5Segmentation fault in tensorflow-lite
CVE-2020-15206Critical· 9.0Denial of Service in Tensorflow
CVE-2020-15193High· 7.1Memory corruption in Tensorflow
CVE-2020-15209Medium· 5.9Null pointer dereference in tensorflow-lite