Back to Paddle

PaddlePaddle Security Advisories

security/README.md

3.3.16.0 KB
Original Source

PaddlePaddle Security Advisories

We regularly publish security advisories about using PaddlePaddle.

Note: In conjunction with these security advisories, we strongly encourage PaddlePaddle users to read and understand PaddlePaddle's security model as outlined in SECURITY.md.

Advisory NumberTypeVersions affectedReported byAdditional Information
PDSA-2023-023Command injection in convert_shape_compare< 2.6.0leeya_bug
PDSA-2023-022FPE in paddle.argmin and paddle.argmax< 2.6.0Peng Zhou (zpbrent) from Shanghai University
PDSA-2023-021Null pointer dereference in paddle.crop< 2.6.0Peng Zhou (zpbrent) from Shanghai University
PDSA-2023-020Command injection in _wget_download< 2.6.0huntr.com
PDSA-2023-019Command injection in get_online_pass_interval< 2.6.0huntr.com and leeya_bug
PDSA-2023-018Heap buffer overflow in paddle.repeat_interleave< 2.6.0Tong Liu of CAS-IIE
PDSA-2023-017FPE in paddle.amin< 2.6.0Tong Liu of CAS-IIE
PDSA-2023-016Stack overflow in paddle.linalg.lu_unpack< 2.6.0Tong Liu of CAS-IIE
PDSA-2023-015FPE in paddle.lerp< 2.6.0Tong Liu of CAS-IIE
PDSA-2023-014FPE in paddle.topk< 2.6.0Tong Liu of CAS-IIE
PDSA-2023-013Stack overflow in paddle.searchsorted< 2.6.0Tong Liu of CAS-IIE
PDSA-2023-012Segfault in paddle.put_along_axis< 2.6.0Tong Liu of CAS-IIE
PDSA-2023-011Null pointer dereference in paddle.nextafter< 2.6.0Tong Liu of CAS-IIE
PDSA-2023-010Segfault in paddle.mode< 2.6.0Tong Liu of CAS-IIE
PDSA-2023-009FPE in paddle.linalg.eig< 2.6.0Tong Liu of CAS-IIE
PDSA-2023-008Segfault in paddle.dot< 2.6.0Tong Liu of CAS-IIE
PDSA-2023-007FPE in paddle.linalg.matrix_rank< 2.6.0Tong Liu of ShanghaiTech University
PDSA-2023-006FPE in paddle.nanmedian< 2.6.0Tong Liu of ShanghaiTech University
PDSA-2023-005Command injection in fs.py< 2.5.0Xiaochen Guo from Huazhong University of Science and Technology
PDSA-2023-004FPE in paddle.linalg.matrix_power< 2.5.0Tong Liu of ShanghaiTech University
PDSA-2023-003Heap buffer overflow in paddle.trace< 2.5.0Tong Liu of ShanghaiTech University
PDSA-2023-002Null pointer dereference in paddle.flip< 2.5.0Tong Liu of ShanghaiTech University
PDSA-2023-001Use after free in paddle.diagonal< 2.5.0Tong Liu of ShanghaiTech University
PDSA-2022-002Code injection in paddle.audio.functional.get_window= 2.4.0-rc0Tong Liu of ShanghaiTech University
PDSA-2022-001OOB read in gather_tree< 2.4Wang Xuan(王旋) of Qihoo 360 AIVul Team