{"id":"CVE-2018-21233","aliases":["GHSA-h98h-8mxr-m8gx","PYSEC-2020-253","PYSEC-2020-269","PYSEC-2020-304"],"url":"https://o3.security/vulnerability/CVE-2018-21233","summary":"Out-of-bounds read in TensorFlow possibly causing disclosure of the contents of process memory.","details":"TensorFlow before 1.7.0 has an integer overflow that causes an out-of-bounds read, possibly causing disclosure of the contents of process memory. This occurs in the DecodeBmp feature of the BMP decoder in core/kernels/decode_bmp_op.cc.","published":"2020-05-04T15:15:13.480Z","modified":"2026-08-07T14:58:57.755393Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"tensorflow","fixedVersion":"1.7.0"},{"ecosystem":"PyPI","name":"tensorflow-gpu","fixedVersion":"1.7.0"}],"fix":{"url":"https://github.com/tensorflow/tensorflow/commit/49f73c55d56edffebde4bca4a407ad69c1cae433","label":"tensorflow/tensorflow@49f73c5"},"references":[{"type":"FIX","url":"https://github.com/tensorflow/tensorflow/blob/master/tensorflow/security/advisory/tfsa-2018-001.md"},{"type":"FIX","url":"https://github.com/tensorflow/tensorflow/commit/49f73c55d56edffebde4bca4a407ad69c1cae433"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:58:57.755393Z"}}