CVE-2020-26266
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/12/2020
Last modified:
14/12/2020
Description
In affected versions of TensorFlow under certain cases a saved model can trigger use of uninitialized values during code execution. This is caused by having tensor buffers be filled with the default value of the type but forgetting to default initialize the quantized floating point types in Eigen. This is fixed in versions 1.15.5, 2.0.4, 2.1.3, 2.2.2, 2.3.2, and 2.4.0.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:* | 1.15.5 (excluding) | |
| cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:* | 2.0.0 (including) | 2.0.4 (excluding) |
| cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:* | 2.1.0 (including) | 2.1.3 (excluding) |
| cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:* | 2.2.0 (including) | 2.2.2 (excluding) |
| cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:* | 2.3.0 (including) | 2.3.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



