VDB
CVE-2020-15210
CVE-2020-15210
PUBLISHED
CVSS 6.5 MEDIUM
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, if a TFLite saved model uses the same tensor as both input and output of an operator, then, depending on the operator, we can observe a segmentation fault or just memory corruption. We have patched the issue in d58c96946b and will release patch releases for all versions between 1.15 and 2.3. We recommend users to upgrade to TensorFlow 1.15.4, 2.0.3, 2.1.2, 2.2.1, or 2.3.1.
EPSS 0.74% · 52.9th percentile
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
EPSS Score
0.74%
52.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | tensorflow | 2.1.0, 0, 2.0.0 |
| Bitnami | tensorflow | 0, 2.0.0, 2.2.0 |
Timeline
- Sep 25, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 25, 2021 EPSS Score
- Oct 28, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 3, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 5, 2022 EPSS Score
- Jul 7, 2022 EPSS Score
- Sep 10, 2022 EPSS Score
References
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00065.html url
- https://github.com/tensorflow/tensorflow/commit/d58c96946b2880991d63d1dacacb32f0a4dfa453 url
- https://github.com/tensorflow/tensorflow/releases/tag/v2.3.1 url
- https://github.com/tensorflow/tensorflow/security/advisories/GHSA-x9j7-x98r-r4w2 url
- https://nvd.nist.gov/vuln/detail/CVE-2020-15210 url