CVE-2023-38669
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jul 26, 2023
Updated: Jul 31, 2023
CWE ID 416
Summary
CVE-2023-38669 is a use-after-free vulnerability affecting the PaddlePaddle library before version 2.5.0. In the function 'paddle.diagonal', an object is not properly managed during memory allocation, resulting in the potential for an attacker to write data to an already freed memory location. This condition may lead to arbitrary code execution or denial of service if successfully exploited. It is recommended that users upgrade to a patched version of PaddlePaddle as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share