CVE-2020-26266
Summary
| CVE | CVE-2020-26266 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-10 23:15:00 UTC |
| Updated | 2020-12-14 17:54:00 UTC |
| Description | In affected versions of TensorFlow under certain cases a saved model can trigger use of uninitialized values during code execution. This is caused by having tensor buffers be filled with the default value of the type but forgetting to default initialize the quantized floating point types in Eigen. This is fixed in versions 1.15.5, 2.0.4, 2.1.3, 2.2.2, 2.3.2, and 2.4.0. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Uninitialized memory access in Eigen types · Advisory · tensorflow/tensorflow · GitHub |
CONFIRM |
github.com |
Exploit, Patch, Third Party Advisory |
| Default initialize fixed point Eigen types. · tensorflow/tensorflow@ace0c15 · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 983228 Python (pip) Security Update for tensorflow-gpu (GHSA-qhxx-j73r-qpm2)