You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The master branch of the AliOS-Things project contains unpatched sources from tflite-micro, in which CVE-2022-35938 was reported with critical severity. The function GatherNd from AliOS-Things/components/ai_agent/src/engine/tflite-micro/tensorflow/lite/micro/kernels/gather_nd.cc does not include security patches and updates available in newer versions of tflite-micro. The fix for CVE can be found in this commit: tflite-micro commit.
To ensure that all security patches are applied, I strongly recommend updating the tflite-micro files in the project to the latest version available.
My report was primarily based on a static analysis tool developed at CAST, which flagged the potential vulnerability due to similarities in the codebase.
Version
master (Default)
What soultions are you seeing the problem on?
No response
Relevant log output
No response
The text was updated successfully, but these errors were encountered:
Contact Details
garnik645@gmail.com
What happened?
The master branch of the AliOS-Things project contains unpatched sources from tflite-micro, in which CVE-2022-35938 was reported with critical severity. The function
GatherNd
fromAliOS-Things/components/ai_agent/src/engine/tflite-micro/tensorflow/lite/micro/kernels/gather_nd.cc
does not include security patches and updates available in newer versions of tflite-micro. The fix for CVE can be found in this commit: tflite-micro commit.To ensure that all security patches are applied, I strongly recommend updating the tflite-micro files in the project to the latest version available.
My report was primarily based on a static analysis tool developed at CAST, which flagged the potential vulnerability due to similarities in the codebase.
Version
master (Default)
What soultions are you seeing the problem on?
No response
Relevant log output
No response
The text was updated successfully, but these errors were encountered: