FPE in paddle.linalg.matrix_rank
CVE-2023-38675

4.7MEDIUM

Key Information:

Vendor
CVE Published:
3 January 2024

What is CVE-2023-38675?

A vulnerability exists in PaddlePaddle within the matrix_rank function, which has significant implications for system stability. Versions prior to 2.6.0 are susceptible to this flaw, potentially leading to runtime crashes and denial of service scenarios. Users of affected versions should take immediate steps to upgrade to the latest release to mitigate the risk of service interruption.

Affected Version(s)

PaddlePaddle 0 < 2.6.0

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.