We found results for “”
CVE-2020-15192
Good to know:
Date: September 25, 2020
In Tensorflow before versions 2.2.1 and 2.3.1, if a user passes a list of strings to "dlpack.to_dlpack" there is a memory leak following an expected validation failure. The issue occurs because the "status" argument during validation failures is not properly checked. Since each of the above methods can return an error status, the "status" value must be checked before continuing. The issue is patched in commit 22e07fb204386768e5bcbea563641ea11f96ceb8 and is released in TensorFlow versions 2.2.1, or 2.3.1.
Language: C++
Severity Score
Related Resources (10)
Severity Score
Weakness Type (CWE)
Improper Input Validation
CWE-20Top Fix
Upgrade Version
Upgrade to version tensorflow-gpu - 2.2.1;tensorflow-gpu - 2.3.1;tensorflow-gpu - 2.2.1;tensorflow - 2.2.1;tensorflow - 2.3.1;tensorflow-cpu - 2.2.1;tensorflow-cpu - 2.3.1
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | NONE |
| Availability (A): | LOW |
CVSS v2
| Base Score: |
|
|---|---|
| Access Vector (AV): | NETWORK |
| Access Complexity (AC): | LOW |
| Authentication (AU): | SINGLE |
| Confidentiality (C): | NONE |
| Integrity (I): | NONE |
| Availability (A): | PARTIAL |
| Additional information: |
Vulnerabilities
Projects
Contact Us


