CVE-2020-26266 - log back

CVE-2020-26266 edited at 16 Dec 2020 20:39:18
Type
- Incorrect calculation
+ Information disclosure
CVE-2020-26266 edited at 15 Dec 2020 13:29:31
References
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-qhxx-j73r-qpm2
- https://github.com/tensorflow/tensorflow/commit/ace0c15a22f7f054abcc1f53eabbcb0a1239a9e2
+ https://github.com/tensorflow/tensorflow/commit/1b3546b184a42ca69b5d094131afd5ff0072d83e
CVE-2020-26266 edited at 11 Dec 2020 14:02:23
References
+ https://github.com/tensorflow/tensorflow/security/advisories/GHSA-qhxx-j73r-qpm2
https://github.com/tensorflow/tensorflow/commit/ace0c15a22f7f054abcc1f53eabbcb0a1239a9e2
CVE-2020-26266 edited at 11 Dec 2020 14:00:48
Severity
- Unknown
+ Low
Remote
- Unknown
+ Local
Type
- Unknown
+ Incorrect calculation
Description
+ In affected versions of TensorFlow under certain cases a saved model can trigger use of uninitialized values during code execution. This is caused by having tensor buffers be filled with the default value of the type but forgetting to default initialize the quantized floating point types in Eigen. This is fixed in versions 1.15.5, 2.0.4, 2.1.3, 2.2.2, 2.3.2, and 2.4.0.
References
+ https://github.com/tensorflow/tensorflow/commit/ace0c15a22f7f054abcc1f53eabbcb0a1239a9e2
Notes
CVE-2020-26266 created at 11 Dec 2020 13:58:53