Skip to content
TensorFlowGHSA-qx2v-j445-g354

Improper Input Validation in Google TensorFlow

High8.1CVE-2018-7577 · Published Apr 30, 2019 · updated Oct 28, 2024

Memcpy parameter overlap in Google Snappy library 1.1.4, as used in Google TensorFlow before 1.7.1, could result in a crash or read from other parts of process memory.

GitHub advisory

Affected versions

PackageAffectedFixed in
tensorflow
PyPI
>= 1.1.0, < 1.7.11.7.1
Details and references

More TensorFlow advisories

All TensorFlow
Advisory
Heap buffer overflow in `UnsortedSegmentSum` in TensorFlow
Low2.6Dec 16, 2019
Improper Restriction of Operations within the Bounds of a Memory Buffer in Google TensorFlow
High8.1Apr 30, 2019
NULL Pointer Dereference in Google TensorFlow
High6.5Apr 30, 2019
Integer Overflow or Wraparound in Google TensorFlow
Critical9.8Apr 30, 2019
Improper Restriction of Operations within the Bounds of a Memory Buffer in Google TensorFlow
High8.8Apr 24, 2019
Null pointer dereference in TensorFlow leads to exploitation
High6.5Apr 24, 2019

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.