CVE-2023-38672

MEDIUM

PaddlePaddle <2.5.0 - Memory Corruption

Title source: llm

Description

FPE in paddle.trace in PaddlePaddle before 2.5.0. This flaw can cause a runtime crash and a denial of service.

Scores

CVSS v3 4.7
EPSS 0.0010
EPSS Percentile 26.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L

Classification

CWE
CWE-369
Status published

Affected Products (2)

paddlepaddle/paddlepaddle < 2.5.0
pypi/paddlepaddle < 2.5.0PyPI

Timeline

Published Jul 26, 2023
Tracked Since Feb 18, 2026