<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T21:15:20.352215+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2020-26267</id>
    <title>CVE-2020-26267 — Lack of validation in data format attributes in TensorFlow</title>
    <updated>2026-10-06T21:15:20.354792+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> tensorflow</p>
<p>In affected versions of TensorFlow the tf.raw_ops.DataFormatVecPermute API does not validate the src_format and dst_format attributes. The code assumes that these two arguments define a permutation of NHWC. This can result in uninitialized memory accesses, read outside of bounds and even crashes. This is fixed in versions 1.15.5, 2.0.4, 2.1.3, 2.2.2, 2.3.2, and 2.4.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2020-26267"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c9f3-9wfr-wgh7</id>
    <title>GHSA-c9f3-9wfr-wgh7 — Lack of validation in data format attributes in TensorFlow</title>
    <updated>2026-10-06T21:15:20.354860+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: tensorflow, PyPI: tensorflow-cpu, PyPI: tensorflow-gpu</p>
<p>### Impact
The `tf.raw_ops.DataFormatVecPermute` API does not validate the `src_format` and `dst_format` attributes. [The code](https://github.com/tensorflow/tensorflow/blob/304b96815324e6a73d046df10df6626d63ac12ad/tensorflow/core/kernels/data_format_ops.cc) assumes that these two arguments define a permutation of `NHWC`.</p>
<p>However, these assumptions are not checked and this can result in uninitialized memory accesses, read outside of bounds and even crashes.</p>
<p>```python
&gt;&gt;&gt; import tensorflow as tf
&gt;&gt;&gt; tf.raw_ops.DataFormatVecPermute(x=[1,4], src_format='1234', dst_format='1234')
&lt;tf.Tensor: shape=(2,), dtype=int32, numpy=array([4, 757100143], dtype=int32)&gt;
...
&gt;&gt;&gt; tf.raw_ops.DataFormatVecPermute(x=[1,4], src_format='HHHH', dst_format='WWWW')
&lt;tf.Tensor: shape=(2,), dtype=int32, numpy=array([4, 32701], dtype=int32)&gt;
...
&gt;&gt;&gt; tf.raw_ops.DataFormatVecPermute(x=[1,4], src_format='H', dst_format='W')
&lt;tf.Tensor: shape=(2,), dtype=int32, numpy=array([4, 32701], dtype=int32)&gt;
&gt;&gt;&gt; tf.raw_ops.DataFormatVecPermute(x=[1,2,3,4], 
                                    src_format='1234', dst_format='1253')
&lt;tf.Tensor: shape=(4,), dtype=int32, numpy=array([4, 2, 939037184, 3], dtype=int32)&gt;
...
&gt;&gt;&gt; tf.raw_ops.DataFormatVecPermute(x=[1,2,3,4],
                                    src_format='1234', dst_format='1223')
&lt;tf.Tensor: shape=(4,), dtype=int32, numpy=array([4, 32701, 2, 3], dtype=int32)&gt;
...
&gt;&gt;&gt; tf.raw_ops.DataFormatVecPermute(x=[1,2,3,4],
                                    src_format=…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c9f3-9wfr-wgh7"/>
  </entry>
</feed>
