Loading HuntDB...

GHSA-9mqp-7v2h-2382

GitHub Security Advisory

Denial of Service in Tensorflow

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

### Impact
The `SparseFillEmptyRowsGrad` implementation has incomplete validation of the shapes of its arguments:
https://github.com/tensorflow/tensorflow/blob/0e68f4d3295eb0281a517c3662f6698992b7b2cf/tensorflow/core/kernels/sparse_fill_empty_rows_op.cc#L235-L241

Although `reverse_index_map_t` and `grad_values_t` are accessed in a similar pattern, only `reverse_index_map_t` is validated to be of proper shape. Hence, malicious users can pass a bad `grad_values_t` to trigger an assertion failure in `vec`, causing denial of service in serving installations.

### Patches
We have patched the issue in 390611e0d45c5793c7066110af37c8514e6a6c54 and will release a patch release for all affected versions.

We recommend users to upgrade to TensorFlow 1.15.4, 2.0.3, 2.1.2, 2.2.1, or 2.3.1.

### For more information
Please consult [our security guide](https://github.com/tensorflow/tensorflow/blob/master/SECURITY.md) for more information regarding the security model and how to contact us with issues and questions.

### Attribution
This vulnerability is a variant of [GHSA-63xm-rx5p-xvqr](https://github.com/tensorflow/tensorflow/security/advisories/GHSA-63xm-rx5p-xvqr)

Affected Packages

PyPI tensorflow
Affected versions: 0 (fixed in 1.15.4)
PyPI tensorflow
Affected versions: 2.0.0 (fixed in 2.0.3)
PyPI tensorflow
Affected versions: 2.1.0 (fixed in 2.1.2)
PyPI tensorflow
Affected versions: 2.2.0 (fixed in 2.2.1)
PyPI tensorflow
Affected versions: 2.3.0 (fixed in 2.3.1)
PyPI tensorflow-cpu
Affected versions: 0 (fixed in 1.15.4)
PyPI tensorflow-cpu
Affected versions: 2.0.0 (fixed in 2.0.3)
PyPI tensorflow-cpu
Affected versions: 2.1.0 (fixed in 2.1.2)
PyPI tensorflow-cpu
Affected versions: 2.2.0 (fixed in 2.2.1)
PyPI tensorflow-cpu
Affected versions: 2.3.0 (fixed in 2.3.1)
PyPI tensorflow-gpu
Affected versions: 0 (fixed in 1.15.4)
PyPI tensorflow-gpu
Affected versions: 2.0.0 (fixed in 2.0.3)
PyPI tensorflow-gpu
Affected versions: 2.1.0 (fixed in 2.1.2)
PyPI tensorflow-gpu
Affected versions: 2.2.0 (fixed in 2.2.1)
PyPI tensorflow-gpu
Affected versions: 2.3.0 (fixed in 2.3.1)

Related CVEs

Key Information

GHSA ID
GHSA-9mqp-7v2h-2382
Published
September 25, 2020 6:28 PM
Last Modified
October 28, 2024 8:02 PM
CVSS Score
5.0 /10
Primary Ecosystem
PyPI
Primary Package
tensorflow
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 2, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.