164 Star 1K Fork 235

MindSpore / community

加入 Gitee
与超过 1200万 开发者一起发现、参与优秀开源项目,私有仓库也完全免费 :)
免费加入
克隆/下载
mssa-2021-007_en.md 806 Bytes
一键复制 编辑 原始数据 按行查看 历史
chengxb7532 提交于 2021-10-26 21:25 . modify spelling mistake

MSSA-2021-007 - Security Advisory

Published Date

2021-10-18

Last Modified Date

2021-10-25

Impact

When performing the inference shape operation of Affine, Concat, MatMul, ArgMinMax, EmbeddingLookup, and Gather operators, if the input shape size is 0, it will access data outside of bounds of shape which allocated from heap buffers.

Patch

We have fixed this issue in version 1.3.0 through commit 8359643b0ebd9d0931110bd7776080abd2f2259d, and created a patch for this vulnerability.

CVE

To be updated.

Attribution

This vulnerability has been reported by Wang Xuan(@May) of Qihoo 360 AIVul Team.

1
https://gitee.com/mindspore/community.git
git@gitee.com:mindspore/community.git
mindspore
community
community
master

搜索帮助