Skip to content
TensorFlowGHSA-qc53-44cj-vfvx

Denial of Service in Tensorflow

Medium6.3CVE-2020-15197 · Published Sep 25, 2020 · updated Jul 8, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
tensorflow
PyPI
>= 2.3.0, < 2.3.12.3.1
Details and references

### Impact The `SparseCountSparseOutput` implementation does not validate that the input arguments form a valid sparse tensor. In particular, there is no validation that the `indices` tensor has rank 2. This tensor must be a matrix because code assumes its elements are accessed as elements of a matrix: https://github.com/tensorflow/tensorflow/blob/0e68f4d3295eb0281a517c3662f6698992b7b2cf/tensorflow/core/kernels/count_ops.cc#L185 However, malicious users can pass in tensors of different rank, resulting in a `CHECK` assertion failure and a crash. This can be used to cause denial of service in serving installations, if users are allowed to control the components of the input sparse tensor. ### Patches We have patched the issue in 3cbb917b4714766030b28eba9fb41bb97ce9ee02 and will release a patch release. We recommend users to upgrade to TensorFlow 2.3.1. ### For more information Please consult [our security guide](https://github.com/tensorflow/tensorflow/blob/master/SECURITY.md) for more information regarding the security model and how to contact us with issues and questions. ### Attribution This vulnerability is a variant of [GHSA-p5f8-gfw5-33w4](https://github.com/tensorflow/tensorflow/security/advisories/GHSA-p5f8-gfw5-33w4)

CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-20, CWE-617
Also known as
BIT-tensorflow-2020-15197, CVE-2020-15197, PYSEC-2020-120, PYSEC-2020-277, PYSEC-2020-312

More TensorFlow advisories

All TensorFlow
DateAdvisory
Sep 252020Segfault in Tensorflow
CVE-2020-15190Medium5.3fixed in 1.15.4, 2.0.3, 2.1.2, 2.2.1
Sep 252020Memory leak in Tensorflow
CVE-2020-15192Medium4.3fixed in 2.2.1, 2.3.1
Sep 252020Denial of Service in Tensorflow
CVE-2020-15194Medium5.3fixed in 1.15.4, 2.0.3, 2.1.2, 2.2.1
Sep 252020Heap buffer overflow in Tensorflow
CVE-2020-15196Medium8.5fixed in 2.3.1
Sep 252020Heap buffer overflow in Tensorflow
CVE-2020-15198Medium5.4fixed in 2.3.1
Sep 252020Denial of Service in Tensorflow
CVE-2020-15199High5.9fixed in 2.3.1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.