Skip to content

Conversation

tensorflow-jenkins
Copy link
Collaborator

Refer to the original commit: 70b7ef2

Due to security issue (a deflate bug when using the `Z_FIXED` strategy can result in out-of-bound accesses), zlib 1.2.11 seems to be yanked, so builds not using TF mirror will break.

See https://www.zlib.net/, https://www.openwall.com/lists/oss-security/2022/03/28/1, https://twitter.com/taviso/status/1508438583484452866 and https://twitter.com/perfinion/status/1508448580226322432?t=e3RC0-DuXNKaEwPnldjzzw&s=03

PiperOrigin-RevId: 437843809
@mihaimaruseac mihaimaruseac merged commit 56f15d1 into r2.8 Apr 18, 2022
@mihaimaruseac mihaimaruseac deleted the r2.8-70b7ef24ee8 branch April 18, 2022 18:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants