VDB
EN

PYSEC-2022-124

상세

Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would allow limited reads and writes outside of arrays in TFLite. This exploits missing validation in the conversion from sparse tensors to dense tensors. The fix is included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow 2.6.3, and TensorFlow 2.5.3, as these are also affected and still in supported range. Users are advised to upgrade as soon as possible.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

PyPI / tensorflow-gpu
최초 영향 버전: 0 수정 버전: 6364463d6f5b6254cac3d6aedf999b6a96225038
수정 pip install --upgrade 'tensorflow-gpu>=6364463d6f5b6254cac3d6aedf999b6a96225038'

참고