-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from insufficient input validation in DiagonalInferMeta. The commit diff shows added validation checks (PADDLE_ENFORCE_GE) for axis1_ and axis2_ to ensure they're non-negative after index adjustment. Prior to 2.5.0, negative-adjusted axes could remain negative if original values were extremely low (e.g., -1000000), leading to invalid memory access when calculating tensor dimensions. This matches the CWE-416 (Use After Free) pattern where improper validation allows access to invalid memory references.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| paddlepaddle | pip | >= 0, < 2.5.0 | 2.5.0 |
Ongoing coverage of React2Shell