REDHAT-BUG-2430027: High severity pypi/keras vulnerability
Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and a crash of the Python interpreter via a crafted .keras archive containing a valid model.weights.h5 file whose dataset declares an extremely large shape.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2430027?
The severity of REDHAT-BUG-2430027 is classified as high with a rating of 7.
How does REDHAT-BUG-2430027 affect the system?
REDHAT-BUG-2430027 allows a remote attacker to cause a Denial of Service (DoS) by exploiting memory exhaustion in the HDF5 weight loading component.
What versions of Keras are impacted by REDHAT-BUG-2430027?
Versions from Google Keras 3.0.0 through 3.13.0 on all platforms are impacted by REDHAT-BUG-2430027.
How can I mitigate the risk of REDHAT-BUG-2430027?
To mitigate the risk of REDHAT-BUG-2430027, ensure that you do not load untrusted .keras archives and monitor memory usage closely.
What type of attack can be performed using REDHAT-BUG-2430027?
An attacker can perform a Denial of Service (DoS) attack that leads to a crash of the Python interpreter through memory exhaustion.