CVE-2020-26270
CHECK-fail in LSTM with zero-length input in TensorFlow
4.4
MEDIUM
CVSS 3.1
EPSS 0.02%
Description
In affected versions of TensorFlow running an LSTM/GRU model where the LSTM/GRU layer receives an input with zero-length results in a CHECK failure when using the CUDA backend. This can result in a query-of-death vulnerability, via denial of service, if users can control the input to the layer. This is fixed in versions 1.15.5, 2.0.4, 2.1.3, 2.2.2, 2.3.2, and 2.4.0.
How to fix CVE-2020-26270
To remediate CVE-2020-26270, upgrade the affected package to a fixed version below.
- —upgrade to 1.15.5 or later
- —upgrade to 1.15.5 or later
- —upgrade to 14755416e364f17fb1870882fa778c7fec7f16e3 or later
- —upgrade to 14755416e364f17fb1870882fa778c7fec7f16e3 or later
- —upgrade to 1.15.5 or later
- —upgrade to 14755416e364f17fb1870882fa778c7fec7f16e3 or later
- —upgrade to 1.15.5 or later
Is CVE-2020-26270 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (7)
- from 0, < 1.15.5, >= 2.0.0, < 2.0.4, >= 2.1.0, < 2.1.3, >= 2.2.0, < 2.2.2, >= 2.3.0, < 2.3.2
- from 0, < 1.15.5
- from 0, < 14755416e364f17fb1870882fa778c7fec7f16e3 | from 0, < 1.15.5, >= 2.0.0, < 2.0.4, >= 2.1.0, < 2.1.3, >= 2.2.0, < 2.2.2, >= 2.3.0, < 2.3.2
- from 0, < 14755416e364f17fb1870882fa778c7fec7f16e3 | from 0, < 1.15.5, >= 2.0.0, < 2.0.4, >= 2.1.0, < 2.1.3, >= 2.2.0, < 2.2.2, >= 2.3.0, < 2.3.2
- from 0, < 1.15.5
- from 0, < 14755416e364f17fb1870882fa778c7fec7f16e3 | from 0, < 1.15.5, >= 2.0.0, < 2.0.4, >= 2.1.0, < 2.1.3, >= 2.2.0, < 2.2.2, >= 2.3.0, < 2.3.2
- from 0, < 1.15.5
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | MEDIUM4.4 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |