BIT-tensorflow-2020-26269

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/tensorflow/BIT-tensorflow-2020-26269.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-tensorflow-2020-26269
Aliases
Published
2024-03-06T11:20:14.848Z
Modified
2024-03-06T11:25:28.861Z
Summary
[none]
Details

In TensorFlow release candidate versions 2.4.0rc*, the general implementation for matching filesystem paths to globbing pattern is vulnerable to an access out of bounds of the array holding the directories. There are multiple invariants and preconditions that are assumed by the parallel implementation of GetMatchingPaths but are not verified by the PRs introducing it (#40861 and #44310). Thus, we are completely rewriting the implementation to fully specify and validate these. This is patched in version 2.4.0. This issue only impacts master branch and the release candidates for TF version 2.4. The final release of the 2.4 release will be patched.

References

Affected packages

Bitnami / tensorflow

Package

Name
tensorflow
Purl
pkg:bitnami/tensorflow

Severity

  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
2.4.0-rc0
Last affected
2.4.0-rc0
Introduced
2.4.0-rc1
Last affected
2.4.0-rc1
Introduced
2.4.0-rc2
Last affected
2.4.0-rc2
Introduced
2.4.0-rc3
Last affected
2.4.0-rc3
Introduced
2.4.0-rc4
Last affected
2.4.0-rc4