CVE-2020-15209: Null pointer dereference in tensorflow-lite
Impact A crafted TFLite model can force a node to have as input a tensor backed by a nullptr buffer. This can be achieved by changing a buffer index in the flatbuffer serialization to convert a read-only tensor to a read-write one. The runtime assumes that these buffers are written to before a possible read, hence they are initialized with nullptr: https://github.com/tensorflow/tensorflow/blob/0e68f4d3295eb0281a517c3662f6698992b7b2cf/tensorflow/lite/core/subgraph.cc#L1224-L1227
However, by changing the buffer index for a tensor and implicitly converting that tensor to be a read-write one, as there is nothing in the model that writes to it, we get a null pointer dereference.
Patches We have patched the issue in 0b5662bc and will release patch releases for all versions between 1.15 and 2.3.
We recommend users to upgrade to TensorFlow 1.15.4, 2.0.3, 2.1.2, 2.2.1, or 2.3.1.
For more information Please consult our security guide for more information regarding the security model and how to contact us with issues and questions.
Attribution This vulnerability has been reported by members of the Aivul Team from Qihoo 360 but was also discovered through variant analysis of GHSA-cvpc-8phh-8f45.
Other sources
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, a crafted TFLite model can force a node to have as input a tensor backed by a nullptr buffer. This can be achieved by changing a buffer index in the flatbuffer serialization to convert a read-only tensor to a read-write one. The runtime assumes that these buffers are written to before a possible read, hence they are initialized with nullptr. However, by changing the buffer index for a tensor and implicitly converting that tensor to be a read-write one, as there is nothing in the model that writes to it, we get a null pointer dereference. The issue is patched in commit 0b5662bc, and is released in TensorFlow versions 1.15.4, 2.0.3, 2.1.2, 2.2.1, or 2.3.1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-15209?
CVE-2020-15209 has been classified as a medium severity vulnerability due to its potential impact on the integrity of the TensorFlow runtime.
How do I fix CVE-2020-15209?
To remediate CVE-2020-15209, upgrade TensorFlow to version 2.3.1 or later.
Which versions of TensorFlow are affected by CVE-2020-15209?
CVE-2020-15209 affects TensorFlow versions 1.15.4, 2.0.0 through 2.0.3, 2.1.0 through 2.1.2, 2.2.0, and 2.3.0.
What types of TensorFlow installations are vulnerable to CVE-2020-15209?
Both CPU and GPU installations of TensorFlow are vulnerable to CVE-2020-15209 if they are running the affected versions.
Is CVE-2020-15209 only a concern for TensorFlow Lite?
Yes, CVE-2020-15209 specifically impacts TensorFlow Lite models that can be maliciously crafted.