---
id: CVE-2020-15212
aliases:
  - GHSA-hx2x-85gr-wrpq
  - BIT-tensorflow-2020-15212
  - PYSEC-2020-135
  - PYSEC-2020-292
  - PYSEC-2020-327
title: Out of bounds access in tensorflow-lite
summary: Out of bounds access in tensorflow-lite
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H'
vendor: tensorflow
product: tensorflow
ecosystem: pip
affected:
  - 'tensorflow >= 2.2.0, < 2.2.1'
  - 'tensorflow >= 2.3.0, < 2.3.1'
  - 'tensorflow-cpu >= 2.2.0, < 2.2.1'
  - 'tensorflow-cpu >= 2.3.0, < 2.3.1'
  - 'tensorflow-gpu >= 2.2.0, < 2.2.1'
  - 'tensorflow-gpu >= 2.3.0, < 2.3.1'
patched:
  - tensorflow 2.2.1
  - tensorflow 2.3.1
  - tensorflow-cpu 2.2.1
  - tensorflow-cpu 2.3.1
  - tensorflow-gpu 2.2.1
  - tensorflow-gpu 2.3.1
published: '2020-09-25'
updated: '2026-07-08'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-hx2x-85gr-wrpq'
references:
  - url: >-
      https://github.com/tensorflow/tensorflow/security/advisories/GHSA-hx2x-85gr-wrpq
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2020-15212'
  - url: >-
      https://github.com/tensorflow/tensorflow/commit/00c7ed7ce81c2126ebc17dfe7073b5c0efd5ec0a
  - url: >-
      https://github.com/tensorflow/tensorflow/commit/204945b19e44b57906c9344c0d00120eeeae178a
  - url: >-
      https://github.com/tensorflow/tensorflow/commit/a4030d8ba3692c438997c27be2dd95f3d5f54827
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/tensorflow-cpu/PYSEC-2020-292.yaml
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/tensorflow-gpu/PYSEC-2020-327.yaml
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/tensorflow/PYSEC-2020-135.yaml
  - url: 'https://github.com/tensorflow/tensorflow'
  - url: >-
      https://github.com/tensorflow/tensorflow/blob/0e68f4d3295eb0281a517c3662f6698992b7b2cf/tensorflow/lite/kernels/internal/reference/reference_ops.h#L2625-L2631
  - url: 'https://github.com/tensorflow/tensorflow/releases/tag/v2.3.1'
tags:
  - osv
  - pip
epss: 0.00737
epssPercentile: 0.52585
ingestedAt: '2026-07-08T18:25:50.339Z'
---

## Overview

### Impact
In TensorFlow Lite models using segment sum can trigger writes outside of bounds of heap allocated buffers by inserting negative elements in the segment ids tensor:
https://github.com/tensorflow/tensorflow/blob/0e68f4d3295eb0281a517c3662f6698992b7b2cf/tensorflow/lite/kernels/internal/reference/reference_ops.h#L2625-L2631

Users having access to `segment_ids_data` can alter `output_index` and then write to outside of `output_data` buffer.

This might result in a segmentation fault but it can also be used to further corrupt the memory and can be chained with other vulnerabilities to create more advanced exploits.

### Patches
We have patched the issue in 204945b and will release patch releases for all affected versions.

We recommend users to upgrade to TensorFlow 2.2.1, or 2.3.1.

### Workarounds
A potential workaround would be to add a custom `Verifier` to the model loading code to ensure that the segment ids are all positive, although this only handles the case when the segment ids are stored statically in the model.

A similar validation could be done if the segment ids are generated at runtime between inference steps.

If the segment ids are generated as outputs of a tensor during inference steps, then there are no possible workaround and users are advised to upgrade to patched code.

### For more information
Please consult [our security guide](https://github.com/tensorflow/tensorflow/blob/master/SECURITY.md) for more information regarding the security model and how to contact us with issues and questions.

### Attribution
This vulnerability has been discovered from a variant analysis of [GHSA-p2cq-cprg-frvm](https://github.com/tensorflow/tensorflow/security/advisories/GHSA-p2cq-cprg-frvm).

## Affected packages

- `tensorflow >= 2.2.0, < 2.2.1`
- `tensorflow >= 2.3.0, < 2.3.1`
- `tensorflow-cpu >= 2.2.0, < 2.2.1`
- `tensorflow-cpu >= 2.3.0, < 2.3.1`
- `tensorflow-gpu >= 2.2.0, < 2.2.1`
- `tensorflow-gpu >= 2.3.0, < 2.3.1`

## Remediation

Upgrade to a patched release:

- `tensorflow 2.2.1`
- `tensorflow 2.3.1`
- `tensorflow-cpu 2.2.1`
- `tensorflow-cpu 2.3.1`
- `tensorflow-gpu 2.2.1`
- `tensorflow-gpu 2.3.1`
