In TensorFlow before 1.15, a heap buffer overflow in UnsortedSegmentSum can be produced when the Index template argument is int32. In this case data_size and num_segments fields are truncated from int64 to int32 and can produce negative numbers, resulting in accessing out of bounds heap memory. This is unlikely to be exploitable and was detected and fixed internally in TensorFlow 1.15 and 2.0.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2019-12-16T20:15:14
Updated: 2024-08-05T01:24:48.540Z
Reserved: 2019-09-24T00:00:00
Link: CVE-2019-16778
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-12-16T21:15:11.403
Modified: 2024-11-21T04:31:10.367
Link: CVE-2019-16778
Redhat
No data.