In Tensorflow before versions 2.2.1 and 2.3.1, if a user passes a list of strings to `dlpack.to_dlpack` there is a memory leak following an expected validation failure. The issue occurs because the `status` argument during validation failures is not properly checked. Since each of the above methods can return an error status, the `status` value must be checked before continuing. The issue is patched in commit 22e07fb204386768e5bcbea563641ea11f96ceb8 and is released in TensorFlow versions 2.2.1, or 2.3.1.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-0188 In Tensorflow before versions 2.2.1 and 2.3.1, if a user passes a list of strings to `dlpack.to_dlpack` there is a memory leak following an expected validation failure. The issue occurs because the `status` argument during validation failures is not properly checked. Since each of the above methods can return an error status, the `status` value must be checked before continuing. The issue is patched in commit 22e07fb204386768e5bcbea563641ea11f96ceb8 and is released in TensorFlow versions 2.2.1, or 2.3.1.
Github GHSA Github GHSA GHSA-8fxw-76px-3rxv Memory leak in Tensorflow
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-04T13:08:22.666Z

Reserved: 2020-06-25T00:00:00

Link: CVE-2020-15192

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-09-25T19:15:14.480

Modified: 2024-11-21T05:05:02.887

Link: CVE-2020-15192

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses