Skip to content
PaddlePaddleGHSA-rr46-m366-gm44

Null pointer dereference in PaddlePaddle

Medium4.7CVE-2023-38670 · Published Jul 26, 2023 · updated Sep 10, 2026

Null pointer dereference in paddle.flip in PaddlePaddle before 2.5.0. This resulted in a runtime crash and denial of service.

GitHub advisory

Affected versions

PackageAffectedFixed in
paddlepaddle
PyPI
< 2.5.02.5.0
Details and references

More PaddlePaddle advisories

All PaddlePaddle
Advisory
PaddlePaddle segfault in paddle.dot
Medium4.7Jan 3, 2024
PaddlePaddle floating point exception in paddle.nanmedian
Medium4.7Jan 3, 2024
Use after free in PaddlePaddle
High8.3Jul 26, 2023
Command injection in PaddlePaddle
Critical9.6Jul 26, 2023
Float point exception (FPE) in paddlepaddle
Medium4.7Jul 26, 2023
Heap buffer overflow in PaddlePaddle
High8.3Jul 26, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.