In Tensorflow before versions 2.2.1 and 2.3.1, the implementation of `dlpack.to_dlpack` can be made to use uninitialized memory resulting in further memory corruption. This is because the pybind11 glue code assumes that the argument is a tensor. However, there is nothing stopping users from passing in a Python object instead of a tensor. The uninitialized memory address is due to a `reinterpret_cast` Since the `PyObject` is a Python object, not a TensorFlow Tensor, the cast to `EagerTensor` fails. The issue is patched in commit 22e07fb204386768e5bcbea563641ea11f96ceb8 and is released in TensorFlow versions 2.2.1, or 2.3.1.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Suse | — | Upgrade tensorflow2Upgrade tensorflow2_2_1_2-gnu-openmpi2-hpc-develUpgrade tensorflow2_2_1_2-gnu-openmpi2-hpc-docUpgrade libtensorflow2-gnu-hpcUpgrade tensorflow2-docUpgrade tensorflow2_2_1_2-gnu-hpc-docUpgrade tensorflow2-lite-develUpgrade libtensorflow_cc2-gnu-openmpi2-hpcUpgrade libtensorflow_cc2-gnu-hpcUpgrade tensorflow2-liteUpgrade libtensorflow2-gnu-openmpi2-hpcUpgrade tensorflow2_2_1_2-gnu-hpcUpgrade libtensorflow_cc2Upgrade libtensorflow_framework2-gnu-hpcUpgrade libtensorflow_framework2Upgrade tensorflow2-gnu-hpcUpgrade libtensorflow2Upgrade tensorflow2_2_1_2-gnu-openmpi2-hpcUpgrade tensorflow2_2_1_2-gnu-hpc-develUpgrade tensorflow2-develUpgrade tensorflow2-gnu-openmpi2-hpcUpgrade libtensorflow_framework2-gnu-openmpi2-hpc | Jun 11, 2021 | Sep 25, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub