First published: Wed Jul 26 2023(Updated: )
Null pointer dereference in paddle.flip in PaddlePaddle before 2.5.0. This resulted in a runtime crash and denial of service.
Credit: paddle-security@baidu.com paddle-security@baidu.com paddle-security@baidu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Paddlepaddle Paddlepaddle | <2.5.0 | |
pip/paddlepaddle | >=0<2.5.0 | 2.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38670 is a vulnerability in PaddlePaddle before version 2.5.0 that allows for a null pointer dereference in the paddle.flip function, resulting in a runtime crash and denial of service.
CVE-2023-38670 has a severity rating of 7.5 (high).
CVE-2023-38670 affects PaddlePaddle versions before 2.5.0, leading to a null pointer dereference and resulting in a runtime crash and denial of service.
To fix CVE-2023-38670 in PaddlePaddle, please update to version 2.5.0 or later.
You can find more information about CVE-2023-38670 in the following references: [GitHub Advisory](https://github.com/PaddlePaddle/Paddle/blob/develop/security/advisory/pdsa-2023-002.md) and [NIST NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-38670).