CVE-2020-15210
Segmentation fault in tensorflow-lite
6.5
MEDIUM
CVSS 3.1
EPSS 0.33%
Description
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, if a TFLite saved model uses the same tensor as both input and output of an operator, then, depending on the operator, we can observe a segmentation fault or just memory corruption. We have patched the issue in d58c96946b and will release patch releases for all versions between 1.15 and 2.3. We recommend users to upgrade to TensorFlow 1.15.4, 2.0.3, 2.1.2, 2.2.1, or 2.3.1.
How to fix CVE-2020-15210
To remediate CVE-2020-15210, upgrade the affected package to a fixed version below.
- —upgrade to 1.15.4 or later
- —upgrade to 1.15.4 or later
- —upgrade to d58c96946b2880991d63d1dacacb32f0a4dfa453 or later
- —upgrade to d58c96946b2880991d63d1dacacb32f0a4dfa453 or later
- —upgrade to 1.15.4 or later
- —upgrade to d58c96946b2880991d63d1dacacb32f0a4dfa453 or later
- —upgrade to 1.15.4 or later
Is CVE-2020-15210 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (7)
- from 0, < 1.15.4, >= 2.0.0, < 2.0.3, >= 2.1.0, < 2.1.2, >= 2.2.0, < 2.2.1, >= 2.3.0, < 2.3.1
- from 0, < 1.15.4
- from 0, < d58c96946b2880991d63d1dacacb32f0a4dfa453 | from 0, < 1.15.4, >= 2.0.0, < 2.0.3, >= 2.1.0, < 2.1.2, >= 2.2.0, < 2.2.1, >= 2.3.0, < 2.3.1
- from 0, < d58c96946b2880991d63d1dacacb32f0a4dfa453 | from 0, < 1.15.4, >= 2.0.0, < 2.0.3, >= 2.1.0, < 2.1.2, >= 2.2.0, < 2.2.1, >= 2.3.0, < 2.3.1
- from 0, < 1.15.4
- from 0, < d58c96946b2880991d63d1dacacb32f0a4dfa453 | from 0, < 1.15.4, >= 2.0.0, < 2.0.3, >= 2.1.0, < 2.1.2, >= 2.2.0, < 2.2.1, >= 2.3.0, < 2.3.1
- from 0, < 1.15.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H |