CVE-2026-2492: TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate by preventing the TensorFlow application from loading plugins from an unsecured location (use a secured, access-controlled directory for plugins).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2492?
CVE-2026-2492 is classified as a local privilege escalation vulnerability.
How do I fix CVE-2026-2492?
To fix CVE-2026-2492, update the TensorFlow HDF5 Library to the latest version that addresses this vulnerability.
Who is affected by CVE-2026-2492?
CVE-2026-2492 affects installations of TensorFlow that utilize the HDF5 library.
Can CVE-2026-2492 be exploited remotely?
No, CVE-2026-2492 requires local access to the vulnerable system to exploit.
What are the implications of CVE-2026-2492?
Exploitation of CVE-2026-2492 can allow attackers to gain elevated privileges on the affected system.