CVE-2020-15190
In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `tf.raw_ops.Switch` operation takes as input a tensor and a boolean and outputs two tensors. Depending on the boolean value, one of the tensors is exactly the input tensor whereas the other one should be an empty tensor. However, the eager runtime traverses all tensors in the output. Since only one of the tensors is defined, the other one is `nullptr`, hence we are binding a reference to `nullptr`. This is undefined behavior and reported as an error if compiling with `-fsanitize=null`. In this case, this results in a segmentation fault The issue is patched in commit da8558533d925694483d2c136a9220d6d49d843c, and is released in TensorFlow versions 1.15.4, 2.0.3, 2.1.2, 2.2.1, or 2.3.1.
EPSS 0.19% · 40.6th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | tensorflow | 2.0.0, 2.1.0, 2.2.0 |
| Bitnami | tensorflow | 0, 2.0.0, 2.1.0 |
Exploit Intelligence
Timeline
- Sep 25, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 18, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
References
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00065.html url
- https://github.com/tensorflow/tensorflow/commit/da8558533d925694483d2c136a9220d6d49d843c url
- https://github.com/tensorflow/tensorflow/releases/tag/v2.3.1 url
- https://github.com/tensorflow/tensorflow/security/advisories/GHSA-4g9f-63rx-5cw4 url
- https://nvd.nist.gov/vuln/detail/CVE-2020-15190 url