Skip to content
PaddlePaddleGHSA-2hvc-hwg3-hpvw

PaddlePaddle Out-of-bounds Read vulnerability

Critical9.1CVE-2022-46741 · Published Dec 7, 2022 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
paddlepaddle
PyPI
< 2.42.4
Details and references

Out-of-bounds read in `gather_tree` in PaddlePaddle before 2.4. A [patch](https://github.com/PaddlePaddle/Paddle/commit/6712e262fc6734873cc6d5ca4f45973339a88697) is available in the `release/2.4` branch.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-125
Also known as
CVE-2022-46741, PYSEC-2026-441

More PaddlePaddle advisories

All PaddlePaddle
DateAdvisory
Dec 72022PaddlePaddle vulnerable to Code Injection
CVE-2022-46742Critical9.8fixed in 2.4.0
Nov 262022PaddlePaddle vulnerable to code injection via winstr
CVE-2022-45908Critical9.8fixed in 2.4
Jul 262023Use after free in PaddlePaddle
CVE-2023-38669High8.3fixed in 2.5.0
Jul 262023Command injection in PaddlePaddle
CVE-2023-38673Critical9.6fixed in 2.5.0
Jul 262023Float point exception (FPE) in paddlepaddle
CVE-2023-38672Medium4.7fixed in 2.5.0
Jul 262023Heap buffer overflow in PaddlePaddle
CVE-2023-38671High8.3fixed in 2.5.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.