CRITICAL9.1
PYSEC-2026-441
PaddlePaddle Out-of-bounds Read vulnerability
Quick fix
PYSEC-2026-441 — paddlepaddle: upgrade to the fixed version with the command below.
pip install --upgrade 'paddlepaddle>=2.4'Details
Out-of-bounds read in `gather_tree` in PaddlePaddle before 2.4. A [patch](https://github.com/PaddlePaddle/Paddle/commit/6712e262fc6734873cc6d5ca4f45973339a88697) is available in the `release/2.4` branch.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-46741[ADVISORY]
- https://github.com/PaddlePaddle/Paddle/pull/47051[WEB]
- https://github.com/PaddlePaddle/Paddle/commit/6712e262fc6734873cc6d5ca4f45973339a88697[WEB]
- https://github.com/PaddlePaddle/Paddle/commit/ee6e6d511f9f33fc862c11722701fb5abb99ed94[WEB]
- https://github.com/PaddlePaddle/Paddle[PACKAGE]
- https://github.com/PaddlePaddle/Paddle/blob/develop/security/advisory/pdsa-2022-001.md[WEB]
- https://pypi.org/project/paddlepaddle[PACKAGE]
- https://github.com/advisories/GHSA-2hvc-hwg3-hpvw[ADVISORY]