CVE-2020-26270
Summary
| CVE | CVE-2020-26270 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-10 23:15:00 UTC |
| Updated | 2020-12-14 17:33:00 UTC |
| Description | In affected versions of TensorFlow running an LSTM/GRU model where the LSTM/GRU layer receives an input with zero-length results in a CHECK failure when using the CUDA backend. This can result in a query-of-death vulnerability, via denial of service, if users can control the input to the layer. This is fixed in versions 1.15.5, 2.0.4, 2.1.3, 2.2.2, 2.3.2, and 2.4.0. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| CHECK-fail in LSTM with zero-length input · Advisory · tensorflow/tensorflow · GitHub |
CONFIRM |
github.com |
Patch, Third Party Advisory |
| Prevent CHECK-fail in LSTM/GRU with zero-length input. · tensorflow/tensorflow@1475541 · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 983230 Python (pip) Security Update for tensorflow-gpu (GHSA-m648-33qf-v3gp)