
Cloud Vulnerability DB
A community-led vulnerabilities database
In TensorFlow before versions 2.2.1 and 2.3.1, if a user passes a list of strings to dlpack.to_dlpack there is a memory leak following an expected validation failure. The issue occurs because the status argument during validation failures is not properly checked. Since each method can return an error status, the status value must be checked before continuing (TF Advisory, NVD).
The vulnerability exists in the DLPack conversion functionality. The memory leak occurs when allocating a new TfDlManagedTensorCtx object but failing to properly check the status value before proceeding with operations that can return error statuses. The issue specifically manifests when passing a list of strings to the dlpack.to_dlpack function, which triggers an expected validation failure but leaks the allocated memory (TF Advisory).
The vulnerability results in memory leaks when certain validation failures occur during DLPack conversion operations. While this does not allow for code execution or data access, it could potentially lead to resource exhaustion over time if triggered repeatedly (TF Advisory).
The vulnerability requires the ability to pass input to the dlpack.to_dlpack function. It is triggered specifically when passing a list of strings, which causes an expected validation failure but results in the memory leak (TF Advisory).
The issue has been patched in TensorFlow versions 2.2.1 and 2.3.1. Users are recommended to upgrade to these patched versions. The fix involves properly checking status values before proceeding with operations that can return error statuses (TF Release, TF Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."