Junglewise Threat Intelligence

CVE-2023-52313: PYSEC-2024-145 - FPE in paddle.argmin and paddle.argmax in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

CVE-2023-52313 · Severity: low · CVSS 3.1 · Published 2024-01-03

Technologies: paddlepaddle (PyPI), PaddlePaddle Paddle. Vendors: PyPI, PaddlePaddle.

Executive brief

PaddlePaddle is a popular machine learning framework used for deep learning and data science tasks. A floating point exception flaw in the argmin and argmax functions can cause the application to crash unexpectedly, disrupting model inference and training operations. An attacker or user providing specially crafted input to these functions could trigger a denial of service.

Technical details

The vulnerability is a floating point exception (FPE / CWE-369) in the paddle.argmin and paddle.argmax functions in PaddlePaddle versions before 2.6.0. The root cause is insufficient input validation that fails to check for invalid arguments before performing division or modulo operations. An attacker can trigger the exception remotely by submitting malformed tensors or invalid axis parameters to these functions, causing a runtime crash and denial of service. No special privileges or authentication are required; the vulnerability requires user interaction to trigger. A fix is available in version 2.6.0.

Affected products

  • PaddlePaddle Paddle before 2.6.0

Timeline

  • 2024-01-03: disclosed
  • 2024-01-03: patched: Fix available in version 2.6.0

References

Related threats