cbcvebase.
CVE-2020-15209
published 2021-05-14

CVE-2020-15209: TensorFlow is an end-to-end open source platform for machine learning. The fix for CVE-2020-15209(https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15209)…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
TensorFlow is an end-to-end open source platform for machine learning. The fix for CVE-2020-15209(https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15209) missed the case when the target shape of `Reshape` operator is given by the elements of a 1-D tensor. As such, the fix for the vulnerability(https://github.com/tensorflow/tensorflow/blob/9c1dc920d8ffb4893d6c9d27d1f039607b326743/tensorflow/lite/core/subgraph.cc#L1062-L1074) allowed passing a null-buffer-backed tensor with a 1D shape. The fix will be included in TensorFlow 2.5.0. We will also cherrypick this commit on TensorFlow 2.4.2, TensorFlow 2.3.3, TensorFlow 2.2.3 and TensorFlow 2.1.4, as these are also affected and still in supported range.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debiantensorflow
googletensorflow< 2.1.42.1.4
googletensorflow< 1.15.41.15.4
googletensorflow>= 2.0.0 < 2.0.32.0.3
googletensorflow>= 2.1.0 < 2.1.22.1.2
googletensorflow>= 2.2.0 < 2.2.32.2.3
googletensorflow>= 2.2.0 < 2.2.12.2.1
googletensorflow>= 2.3.0 < 2.3.32.3.3
googletensorflow>= 2.3.0 < 2.3.12.3.1
googletensorflow>= 2.4.0 < 2.4.22.4.2
inteloptimization_for_tensorflow>= 0 < 1.15.41.15.4
inteloptimization_for_tensorflow>= 0 < 2.1.42.1.4
inteloptimization_for_tensorflow>= 0 < f8378920345f4f4604202d4ab15ef64b2aceaa16f8378920345f4f4604202d4ab15ef64b2aceaa16
inteloptimization_for_tensorflow>= 0 < 0b5662bc2be13a8c8f044d925d87fb6e56247cd80b5662bc2be13a8c8f044d925d87fb6e56247cd8
inteloptimization_for_tensorflow>= 2.0.0 < 2.0.32.0.3
inteloptimization_for_tensorflow>= 2.1.0 < 2.1.22.1.2
inteloptimization_for_tensorflow>= 2.2.0 < 2.2.12.2.1
inteloptimization_for_tensorflow>= 2.2.0 < 2.2.32.2.3
inteloptimization_for_tensorflow>= 2.3.0 < 2.3.12.3.1
inteloptimization_for_tensorflow>= 2.3.0 < 2.3.32.3.3
inteloptimization_for_tensorflow>= 2.4.0 < 2.4.22.4.2
opensuseleap
tensorflowtensorflow< 2.1.42.1.4
tensorflowtensorflow
tensorflowtensorflow

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ghsa5.9MEDIUM
osv5.9MEDIUM