CVE-2021-33650

HIGH

SparseToDense - Memory Corruption

Title source: llm
STIX 2.1

Description

When performing the inference shape operation of the SparseToDense operator, if the number of inputs is less than three, it will access data outside of bounds of inputs which allocated from heap buffers.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0032
EPSS Percentile 54.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-125
Status published
Products (1)
mindspore/mindspore 1.2.0 - 1.3.0
Published Jun 27, 2022
Tracked Since Feb 18, 2026