Oval Definition:oval:org.opensuse.security:def:202015209
Revision Date:2022-06-30Version:1
Title:CVE-2020-15209
Description:

In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, a crafted TFLite model can force a node to have as input a tensor backed by a `nullptr` buffer. This can be achieved by changing a buffer index in the flatbuffer serialization to convert a read-only tensor to a read-write one. The runtime assumes that these buffers are written to before a possible read, hence they are initialized with `nullptr`. However, by changing the buffer index for a tensor and implicitly converting that tensor to be a read-write one, as there is nothing in the model that writes to it, we get a null pointer dereference. The issue is patched in commit 0b5662bc, and is released in TensorFlow versions 1.15.4, 2.0.3, 2.1.2, 2.2.1, or 2.3.1.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2020-15209
openSUSE-SU-2020:1766-1
Mitre CVE-2020-15209
SUSE CVE-2020-15209
openSUSE-SU-2020:1766-1
Platform(s):openSUSE Leap 15.2
openSUSE Tumbleweed
Product(s):
Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • libtensorflow2-2.1.2-lp152.7.3.1 is installed
  • AND libtensorflow2 is signed with openSUSE key
  • OR
  • libtensorflow2-gnu-hpc-2.1.2-lp152.7.3.1 is installed
  • AND libtensorflow2-gnu-hpc is signed with openSUSE key
  • OR
  • libtensorflow2-gnu-openmpi2-hpc-2.1.2-lp152.7.3.1 is installed
  • AND libtensorflow2-gnu-openmpi2-hpc is signed with openSUSE key
  • OR
  • libtensorflow_cc2-2.1.2-lp152.7.3.1 is installed
  • AND libtensorflow_cc2 is signed with openSUSE key
  • OR
  • libtensorflow_cc2-gnu-hpc-2.1.2-lp152.7.3.1 is installed
  • AND libtensorflow_cc2-gnu-hpc is signed with openSUSE key
  • OR
  • libtensorflow_cc2-gnu-openmpi2-hpc-2.1.2-lp152.7.3.1 is installed
  • AND libtensorflow_cc2-gnu-openmpi2-hpc is signed with openSUSE key
  • OR
  • libtensorflow_framework2-2.1.2-lp152.7.3.1 is installed
  • AND libtensorflow_framework2 is signed with openSUSE key
  • OR
  • libtensorflow_framework2-gnu-hpc-2.1.2-lp152.7.3.1 is installed
  • AND libtensorflow_framework2-gnu-hpc is signed with openSUSE key
  • OR
  • libtensorflow_framework2-gnu-openmpi2-hpc-2.1.2-lp152.7.3.1 is installed
  • AND libtensorflow_framework2-gnu-openmpi2-hpc is signed with openSUSE key
  • OR
  • tensorflow2-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2 is signed with openSUSE key
  • OR
  • tensorflow2-devel-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2-devel is signed with openSUSE key
  • OR
  • tensorflow2-doc-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2-doc is signed with openSUSE key
  • OR
  • tensorflow2-gnu-hpc-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2-gnu-hpc is signed with openSUSE key
  • OR
  • tensorflow2-gnu-openmpi2-hpc-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2-gnu-openmpi2-hpc is signed with openSUSE key
  • OR
  • tensorflow2-lite-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2-lite is signed with openSUSE key
  • OR
  • tensorflow2-lite-devel-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2-lite-devel is signed with openSUSE key
  • OR
  • tensorflow2_2_1_2-gnu-hpc-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2_2_1_2-gnu-hpc is signed with openSUSE key
  • OR
  • tensorflow2_2_1_2-gnu-hpc-devel-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2_2_1_2-gnu-hpc-devel is signed with openSUSE key
  • OR
  • tensorflow2_2_1_2-gnu-hpc-doc-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2_2_1_2-gnu-hpc-doc is signed with openSUSE key
  • OR
  • tensorflow2_2_1_2-gnu-openmpi2-hpc-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2_2_1_2-gnu-openmpi2-hpc is signed with openSUSE key
  • OR
  • tensorflow2_2_1_2-gnu-openmpi2-hpc-devel-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2_2_1_2-gnu-openmpi2-hpc-devel is signed with openSUSE key
  • OR
  • tensorflow2_2_1_2-gnu-openmpi2-hpc-doc-2.1.2-lp152.7.3.1 is installed
  • AND tensorflow2_2_1_2-gnu-openmpi2-hpc-doc is signed with openSUSE key
  • Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND Package Information
  • tensorflow-lite-2.9.1-1.1 is installed
  • OR tensorflow-lite-devel-2.9.1-1.1 is installed
  • BACK