BIT-tensorflow-2020-26269

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/tensorflow/BIT-tensorflow-2020-26269.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-tensorflow-2020-26269
Aliases
Published
2024-03-06T11:20:14.848Z
Modified
2025-03-24T17:31:38.612Z
Summary
[none]
Details

In TensorFlow release candidate versions 2.4.0rc*, the general implementation for matching filesystem paths to globbing pattern is vulnerable to an access out of bounds of the array holding the directories. There are multiple invariants and preconditions that are assumed by the parallel implementation of GetMatchingPaths but are not verified by the PRs introducing it (#40861 and #44310). Thus, we are completely rewriting the implementation to fully specify and validate these. This is patched in version 2.4.0. This issue only impacts master branch and the release candidates for TF version 2.4. The final release of the 2.4 release will be patched.

Database specific
{
    "cpes": [
        "cpe:2.3:a:google:tensorflow:2.4.0:rc0:*:*:*:*:*:*",
        "cpe:2.3:a:google:tensorflow:2.4.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:google:tensorflow:2.4.0:rc2:*:*:*:*:*:*",
        "cpe:2.3:a:google:tensorflow:2.4.0:rc3:*:*:*:*:*:*",
        "cpe:2.3:a:google:tensorflow:2.4.0:rc4:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / tensorflow

Package

Name
tensorflow
Purl
pkg:bitnami/tensorflow

Severity

  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
2.4.0-rc0
Fixed
2.4.0
Introduced
2.4.0-rc1
Fixed
2.4.0
Introduced
2.4.0-rc2
Fixed
2.4.0
Introduced
2.4.0-rc3
Fixed
2.4.0
Introduced
2.4.0-rc4
Fixed
2.4.0