Skip to content
PaddlePaddleGHSA-hh7p-hvm3-rg88

Heap buffer overflow in PaddlePaddle

High8.3CVE-2023-38671 · Published Jul 26, 2023 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
paddlepaddle
PyPI
< 2.5.02.5.0
Details and references

Heap buffer overflow in paddle.trace in PaddlePaddle before 2.5.0. This flaw can lead to a denial of service, information disclosure, or more damage is possible.

CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-120, CWE-787
Also known as
CVE-2023-38671, PYSEC-2023-124

More PaddlePaddle advisories

All PaddlePaddle
DateAdvisory
Jul 262023Use after free in PaddlePaddle
CVE-2023-38669High8.3fixed in 2.5.0
Jul 262023Command injection in PaddlePaddle
CVE-2023-38673Critical9.6fixed in 2.5.0
Jul 262023Float point exception (FPE) in paddlepaddle
CVE-2023-38672Medium4.7fixed in 2.5.0
Jul 262023Null pointer dereference in PaddlePaddle
CVE-2023-38670Medium4.7fixed in 2.5.0
Jan 32024PaddlePaddle floating point exception in paddle.nanmedian
CVE-2023-38674Medium4.7fixed in 2.6.0
Jan 32024PaddlePaddle segfault in paddle.put_along_axis
CVE-2023-52303Medium4.7fixed in 2.6.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.