CVE-2020-15209Medium· 5.9▾ SunlitNull pointer dereference in tensorflow-lite
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.8%
A crafted TFLite model can force a node to have as input a tensor backed by a nullptr buffer. This can be achieved by changing a buffer index in the flatbuffer serialization to convert a read-only tensor to a read-write one. The runtime assumes that these buffers are written to before a possible read, hence they are initialized with nullptr:
https://github.com/tensorflow/tensorflow/blob/0e68f4d3295eb0281a517c3662f6698992b7b2cf/tensorflow/lite/core/subgraph.cc#L1224-L1227
However, by changing the buffer index for a tensor and implicitly converting that tensor to be a read-write one, as there is nothing in the model that writes to it, we get a null pointer dereference.
We have patched the issue in 0b5662bc and will release patch releases for all versions between 1.15 and 2.3.
We recommend users to upgrade to TensorFlow 1.15.4, 2.0.3, 2.1.2, 2.2.1, or 2.3.1.
Please consult our security guide for more information regarding the security model and how to contact us with issues and questions.
This vulnerability has been reported by members of the Aivul Team from Qihoo 360 but was also discovered through variant analysis of GHSA-cvpc-8phh-8f45.
tensorflow < 1.15.4tensorflow >= 2.0.0, < 2.0.3tensorflow >= 2.1.0, < 2.1.2tensorflow >= 2.2.0, < 2.2.1tensorflow >= 2.3.0, < 2.3.1tensorflow-cpu < 1.15.4tensorflow-cpu >= 2.0.0, < 2.0.3tensorflow-cpu >= 2.1.0, < 2.1.2tensorflow-cpu >= 2.2.0, < 2.2.1tensorflow-cpu >= 2.3.0, < 2.3.1tensorflow-gpu < 1.15.4tensorflow-gpu >= 2.0.0, < 2.0.3tensorflow-gpu >= 2.1.0, < 2.1.2tensorflow-gpu >= 2.2.0, < 2.2.1tensorflow-gpu >= 2.3.0, < 2.3.1Upgrade to a patched release:
tensorflow 1.15.4tensorflow 2.0.3tensorflow 2.1.2tensorflow 2.2.1tensorflow 2.3.1tensorflow-cpu 1.15.4tensorflow-cpu 2.0.3tensorflow-cpu 2.1.2tensorflow-cpu 2.2.1tensorflow-cpu 2.3.1tensorflow-gpu 1.15.4tensorflow-gpu 2.0.3tensorflow-gpu 2.1.2tensorflow-gpu 2.2.1tensorflow-gpu 2.3.1Connected by shared product, vendor, weakness, or advisory.
CVE-2020-15207High· 8.7Segfault and data corruption in tensorflow-lite
CVE-2020-15203High· 7.5Denial of Service in Tensorflow
CVE-2020-15210Medium· 6.5Segmentation fault in tensorflow-lite
CVE-2020-15206Critical· 9.0Denial of Service in Tensorflow
CVE-2020-15193High· 7.1Memory corruption in Tensorflow
CVE-2020-15191Medium· 5.3Undefined behavior in Tensorflow