Executive brief
PaddlePaddle is a popular machine learning framework used for deep learning and data science tasks. A floating point exception flaw in the argmin and argmax functions can cause the application to crash unexpectedly, disrupting model inference and training operations. An attacker or user providing specially crafted input to these functions could trigger a denial of service.
Technical details
The vulnerability is a floating point exception (FPE / CWE-369) in the paddle.argmin and paddle.argmax functions in PaddlePaddle versions before 2.6.0. The root cause is insufficient input validation that fails to check for invalid arguments before performing division or modulo operations. An attacker can trigger the exception remotely by submitting malformed tensors or invalid axis parameters to these functions, causing a runtime crash and denial of service. No special privileges or authentication are required; the vulnerability requires user interaction to trigger. A fix is available in version 2.6.0.
Affected products
- PaddlePaddle Paddle before 2.6.0
Timeline
- 2024-01-03: disclosed
- 2024-01-03: patched: Fix available in version 2.6.0