QID 980176
QID 980176: Python (pip) Security Update for tensorflow-gpu (GHSA-cvgx-3v3q-m36c)
Security update has been released for tensorflow-gpu,tensorflow,tensorflow-cpu to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
The [shape inference code for `QuantizeV2`](https://github.com/tensorflow/tensorflow/blob/8d72537c6abf5a44103b57b9c2e22c14f5f49698/tensorflow/core/framework/common_shape_fns.cc#L2509-L2530) can trigger a read outside of bounds of heap allocated array:
```python
import tensorflow as tf
@tf.function
def test():
data=tf.raw_ops.QuantizeV2(
input=[1.0,1.0],
min_range=[1.0,10.0],
max_range=[1.0,10.0],
T=tf.qint32,
mode='MIN_COMBINED',
round_mode='HALF_TO_EVEN',
narrow_range=False,
axis=-100,
ensure_minimum_range=10)
return data
test()
```
This occurs whenever `axis` is a negative value less than `-1`. In this case, we are accessing data before the start of a heap buffer:
```cc
int axis = -1;
Status s = c->GetAttr("axis", &axis);
if (!s.ok() && s.code() != error::NOT_FOUND) {
return s;
}
...
if (axis != -1) {
...
TF_RETURN_IF_ERROR(
c->Merge(c->Dim(minmax, 0), c->Dim(input, axis), &depth));
}
```
The code allows `axis` to be an optional argument (`s` would contain an `error::NOT_FOUND` error code). Otherwise, it assumes that `axis` is a valid index into the dimensions of the `input` tensor. If `axis` is less than `-1` then this results in a heap OOB read.
The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, as this version is the only one that is also affected.
- GHSA-cvgx-3v3q-m36c -
github.com/advisories/GHSA-cvgx-3v3q-m36c
CVEs related to QID 980176
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cvgx-3v3q-m36c | tensorflow |
|
|
| GHSA-cvgx-3v3q-m36c | tensorflow-cpu |
|
|
| GHSA-cvgx-3v3q-m36c | tensorflow-gpu |
|