Paddle rocksdb has vulnerability issues

aiazj4mn  于 2个月前  发布在  其他
关注(0)|答案(1)|浏览(27)

bug描述 Describe the Bug

PaddlePaddle uses a 3rd-party library - rocksdb (version 9e18bf0), which is very old.
NVIDIA found that it has multiple vulnerability issues, such as

  • BDSA-2023-1616 (rocksdb/Ruby on Rails)
  • BDSA-2023-0529 (rocksdb/Ruby on Rails)
  • BDSA-2023-0528 (rocksdb/Ruby on Rails)
  • BDSA-2022-1946 (rocksdb/Ruby on Rails)
  • BDSA-2022-1489 (rocksdb/Ruby on Rails)
  • BDSA-2021-2526 (rocksdb/Ruby on Rails)
  • BDSA-2021-0393 (rocksdb/Ruby on Rails)
  • BDSA-2020-1121 (rocksdb/Ruby on Rails)
  • BDSA-2022-3324 (rocksdb/TZInfo)
  • CVE-2024-22051 (rocksdb/commonmarker)

其他补充信息 Additional Supplementary Information

No response

jxct1oxe

jxct1oxe1#

Thanks for reminding us. Which version is stable and invulnerable, 9.x.fb is ok?

相关问题