Skip to content
TensorFlowGHSA-mw6v-crh8-8533

Integer Overflow or Wraparound in Google TensorFlow

Critical9.8CVE-2018-7575 · Published Apr 30, 2019 · updated Oct 28, 2024

### Issue Description Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerability. The type of exploitation is context-dependent. The block size in meta file might contain a large int64 value which causes an integer overflow upon addition. Subsequent code using n as index may cause an out-of-bounds read. ### Impact A maliciously crafted meta checkpoint could be used to cause the TensorFlow process to perform an out of bounds read on in process memory.

GitHub advisory

Affected versions

PackageAffectedFixed in
tensorflow
PyPI
>= 1.0.0, < 1.7.11.7.1
Details and references

More TensorFlow advisories

All TensorFlow
Advisory
Heap buffer overflow in `UnsortedSegmentSum` in TensorFlow
Low2.6Dec 16, 2019
Improper Input Validation in Google TensorFlow
High8.1Apr 30, 2019
Improper Restriction of Operations within the Bounds of a Memory Buffer in Google TensorFlow
High8.1Apr 30, 2019
NULL Pointer Dereference in Google TensorFlow
High6.5Apr 30, 2019
Improper Restriction of Operations within the Bounds of a Memory Buffer in Google TensorFlow
High8.8Apr 24, 2019
Null pointer dereference in TensorFlow leads to exploitation
High6.5Apr 24, 2019

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.