QID 983230
QID 983230: Python (pip) Security Update for tensorflow-gpu (GHSA-m648-33qf-v3gp)
Security update has been released for tensorflow,tensorflow-cpu,tensorflow-gpu to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Running an LSTM/GRU model where the LSTM/GRU layer receives an input with zero-length results in a `CHECK` failure when using the CUDA backend.
This can result in a query-of-death vulnerability, via denial of service, if users can control the input to the layer.
Solution
We have patched the issue in GitHub commit [14755416e364f17fb1870882fa778c7fec7f16e3](https://github.com/tensorflow/tensorflow/commit/14755416e364f17fb1870882fa778c7fec7f16e3) and will release TensorFlow 2.4.0 containing the patch. TensorFlow nightly packages after this commit will also have the issue resolved.
Since this issue also impacts TF versions before 2.4, we will patch all releases between 1.15 and 2.3 inclusive.
Since this issue also impacts TF versions before 2.4, we will patch all releases between 1.15 and 2.3 inclusive.
Vendor References
- GHSA-m648-33qf-v3gp -
github.com/advisories/GHSA-m648-33qf-v3gp
CVEs related to QID 983230
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-m648-33qf-v3gp | tensorflow |
|
|
| GHSA-m648-33qf-v3gp | tensorflow-cpu |
|
|
| GHSA-m648-33qf-v3gp | tensorflow-gpu |
|