CVE-2020-5215 (CNNVD-202001-1281)
中文标题:
Google TensorFlow 输入验证错误漏洞
英文标题:
Segmentation faultin TensorFlow when converting a Python string to tf.float16
漏洞描述
中文描述:
Google TensorFlow是美国谷歌(Google)公司的一套用于机器学习的端到端开源平台。 Google TensorFlow 1.15.2之前版本和2.0.1之前版本中字符串(从Python)转换为tf.float16类型的过程存在输入验证错误漏洞。远程攻击者可借助特制字符串利用该漏洞造成段错误。
英文描述:
In TensorFlow before 1.15.2 and 2.0.1, converting a string (from Python) to a tf.float16 value results in a segmentation fault in eager mode as the format checks for this use case are only in the graph mode. This issue can lead to denial of service in inference/training where a malicious attacker can send a data point which contains a string instead of a tf.float16 value. Similar effects can be obtained by manipulating saved models and checkpoints whereby replacing a scalar tf.float16 value with a scalar string will trigger this issue due to automatic conversions. This can be easily reproduced by tf.constant("hello", tf.float16), if eager execution is enabled. This issue is patched in TensorFlow 1.15.1 and 2.0.1 with this vulnerability patched. TensorFlow 2.1.0 was released after we fixed the issue, thus it is not affected. Users are encouraged to switch to TensorFlow 1.15.1, 2.0.1 or 2.1.0.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| TensorFlow | TensorFlow | < 1.15.2 | - | - |
cpe:2.3:a:tensorflow:tensorflow:<_1.15.2:*:*:*:*:*:*:*
|
| TensorFlow | TensorFlow | = 2.0.0 | - | - |
cpe:2.3:a:tensorflow:tensorflow:=_2.0.0:*:*:*:*:*:*:*
|
| tensorflow | * | - | - |
cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
3.1 (cna)
MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2020-5215 |
2025-11-11 15:20:39 | 2025-11-11 07:36:24 |
| NVD | nvd_CVE-2020-5215 |
2025-11-11 14:56:55 | 2025-11-11 07:44:47 |
| CNNVD | cnnvd_CNNVD-202001-1281 |
2025-11-11 15:10:21 | 2025-11-11 07:55:20 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 输入验证错误
- cnnvd_id: 未提取 -> CNNVD-202001-1281
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 2 -> 3
- data_sources: ['cve'] -> ['cve', 'nvd']