
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-15194 is a vulnerability in TensorFlow's SparseFillEmptyRowsGrad implementation that was disclosed on September 24, 2020. The vulnerability stems from incomplete validation of argument shapes, affecting TensorFlow versions prior to 2.3.0 (GitHub Advisory).
The vulnerability exists in the SparseFillEmptyRowsGrad implementation where only reverse_index_map_t is validated to be of proper shape, while grad_values_t is accessed without proper shape validation. This occurs in the tensorflow/tensorflow/core/kernels/sparse_fill_empty_rows_op.cc file (GitHub Commit).
The vulnerability can allow malicious users to pass malformed grad_values_t parameters to trigger an assertion failure in the vec function, potentially causing denial of service in serving installations (GitHub Advisory).
The vulnerability can be exploited by passing a bad grad_values_t parameter to the SparseFillEmptyRowsGrad operation. This is a variant of another vulnerability (GHSA-63xm-rx5p-xvqr) (GitHub Advisory).
The issue was patched in TensorFlow versions 1.15.4, 2.0.3, 2.1.2, 2.2.1, and 2.3.1. Users are recommended to upgrade to these patched versions. The fix includes proper validation of the grad_values shape (GitHub Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."