Home
Description
A device-ID validation flaw in OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) by calling flow.cuda.synchronize() with an invalid or out-of-range GPU device index.
References
github.com/Oneflow-Inc/oneflow
github.com/Oneflow-Inc/oneflow/issues/10662