VDB
CVE-2020-15210
CVE-2020-15210
PUBLISHED
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, if a TFLite saved model uses the same tensor as both input and output of an operator, then, depending on the operator, we can observe a segmentation fault or just memory corruption. We have patched the issue in d58c96946b and will release patch releases for all versions between 1.15 and 2.3. We recommend users to upgrade to TensorFlow 1.15.4, 2.0.3, 2.1.2, 2.2.1, or 2.3.1.
EPSS 0.33% · 56.2th percentile
Risk Scores
EPSS Score
0.33%
56.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | tensorflow | 2.1.0, 0, 2.0.0 |
| Bitnami | tensorflow | 0, 2.0.0, 2.2.0 |
Exploit Intelligence
Timeline
- Sep 25, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
References
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00065.html url
- https://github.com/tensorflow/tensorflow/commit/d58c96946b2880991d63d1dacacb32f0a4dfa453 url
- https://github.com/tensorflow/tensorflow/releases/tag/v2.3.1 url
- https://github.com/tensorflow/tensorflow/security/advisories/GHSA-x9j7-x98r-r4w2 url
- https://nvd.nist.gov/vuln/detail/CVE-2020-15210 url