PT-2026-59771 · Pypi · Tensorflow

Publicado

2026-07-09

·

Atualizado

2026-07-09

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Impact

Under certain scenarios, Grappler component of TensorFlow can trigger a null pointer dereference. There are 2 places where this can occur, for the same malicious alteration of a SavedModel file (fixing the first one would trigger the same dereference in the second place):
First, during [constant folding](https://github.com/tensorflow/tensorflow/blob/a1320ec1eac186da1d03f033109191f715b2b130/tensorflow/core/grappler/optimizers/constant folding.cc#L3466-L3497), the GraphDef might not have the required nodes for the binary operation:
cc
 NodeDef* mul left child = node map ->GetNode(node->input(0));
 NodeDef* mul right child = node map ->GetNode(node->input(1));
 // One child must be constant, and the second must be Conv op.
 const bool left child is constant = IsReallyConstant(*mul left child);
 const bool right child is constant = IsReallyConstant(*mul right child);
If a node is missing, the correposning mul *child would be null, and the dereference in the subsequent line would be incorrect.
We have a similar issue during [IsIdentityConsumingSwitch](https://github.com/tensorflow/tensorflow/blob/a1320ec1eac186da1d03f033109191f715b2b130/tensorflow/core/grappler/mutable graph view.cc#L59-L74):
cc
 NodeDef* input node = graph.GetNode(tensor id.node());
 return IsSwitch(*input node);

Patches

The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow 2.6.3, and TensorFlow 2.5.3, as these are also affected and still in supported range.

For more information

Please consult our security guide for more information regarding the security model and how to contact us with issues and questions.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

PYSEC-2026-3154

Produtos afetados

Tensorflow