CVE-2018-7576: Null Pointer Dereference
Published Apr 23, 2019
·Updated
Google TensorFlow 1.0.0 through 1.5.1 is affected by: Null Pointer Dereference. The type of exploitation is: context-dependent.
Other sources
Google TensorFlow 1.6.x and earlier is affected by: Null Pointer Dereference. The type of exploitation is: context-dependent.
Affected Software
3 affected componentsFixes available
pip/tensorflow-gpu>=1.0.0<1.6.0
1.6.0
pip/tensorflow>=1.0.0<1.6.0
1.6.0
Google TensorFlow<=1.6.0
Remediation
Event History
Apr 23, 2019
CVE Published
via MITRE·08:44 PM
Data Sourced
via MITRE·08:44 PM
Description
Apr 24, 2019
Advisory Published
via GitHub·04:11 PM
Frequently Asked Questions
1
What is the severity of CVE-2018-7576?
CVE-2018-7576 has a context-dependent severity due to the Null Pointer Dereference vulnerability in Google TensorFlow.
2
How do I fix CVE-2018-7576?
To fix CVE-2018-7576, upgrade your Google TensorFlow version to 1.6.0 or later.
3
Which versions of TensorFlow are affected by CVE-2018-7576?
Google TensorFlow versions from 1.0.0 through 1.6.0 are affected by CVE-2018-7576.
4
What type of vulnerability is CVE-2018-7576?
CVE-2018-7576 is characterized as a Null Pointer Dereference vulnerability.
5
Is CVE-2018-7576 exploitable in all environments?
CVE-2018-7576 is context-dependent, meaning it may only be exploitable under certain conditions.