QID 983114
QID 983114: Python (pip) Security Update for tensorflow-gpu (GHSA-977j-xj7q-2jr9)
Security update has been released for tensorflow,tensorflow-cpu,tensorflow-gpu to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Converting a string (from Python) to a `tf.float16` value results in a segmentation fault in eager mode as the format checks for this use case are only in the graph mode.
This issue can lead to denial of service in inference/training where a malicious attacker can send a data point which contains a string instead of a `tf.float16` value.
Similar effects can be obtained by manipulating saved models and checkpoints whereby replacing a scalar `tf.float16` value with a scalar string will trigger this issue due to automatic conversions.
This can be easily reproduced by `tf.constant("hello", tf.float16)`, if eager execution is enabled.
We are additionally releasing TensorFlow 1.15.1 and 2.0.1 with this vulnerability patched.
TensorFlow 2.1.0 was released after we fixed the issue, thus it is not affected.
We encourage users to switch to TensorFlow 1.15.1, 2.0.1 or 2.1.0.
- GHSA-977j-xj7q-2jr9 -
github.com/advisories/GHSA-977j-xj7q-2jr9
CVEs related to QID 983114
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-977j-xj7q-2jr9 | tensorflow |
|
|
| GHSA-977j-xj7q-2jr9 | tensorflow-cpu |
|
|
| GHSA-977j-xj7q-2jr9 | tensorflow-gpu |
|