VYPR
High severity8.1OSV Advisory· Published Apr 24, 2019· Updated Jun 17, 2026

CVE-2018-7577

CVE-2018-7577

Description

Memcpy parameter overlap in Google Snappy library 1.1.4, as used in Google TensorFlow before 1.7.1, could result in a crash or read from other parts of process memory.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
tensorflowPyPI
>= 1.1.0, < 1.7.11.7.1
tensorflow-gpuPyPI
>= 1.1.0, < 1.7.11.7.1

Affected products

5
  • Google/SnappyOSV2 versions
    0.5.0, 0.6.0, 1.1.3, …+ 1 more
    • (no CPE)range: 0.5.0, 0.6.0, 1.1.3, …
    • cpe:2.3:a:google:snappy:1.1.4:*:*:*:*:*:*:*
  • cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:*
    Range: <1.7.1
  • ghsa-coords2 versions
    >= 1.1.0, < 1.7.1+ 1 more
    • (no CPE)range: >= 1.1.0, < 1.7.1
    • (no CPE)range: >= 1.1.0, < 1.7.1

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.