Skip to content

Vulnerability: CVE-2024-27763 #729

Description

@knitvoger

Is there any plan to fix this vulnerability? Will this be fix soon?

Activity

  1. christopher5106 commented on Aug 12, 2026

    @christopher5106

    I've opened #765 with a fix, in case it's useful.

    For anyone landing here from the advisory, the concrete details:

    The single sink is basicsr/utils/dist_util.py, in _init_dist_slurm:

    addr = subprocess.getoutput(f'scontrol show hostname {node_list} | head -n1')

    node_list is os.environ['SLURM_NODELIST'], and subprocess.getoutput runs
    its argument through /bin/sh -c, so shell metacharacters in that variable are
    interpreted. This is the only getoutput call in the codebase, and the fix is to
    pass the node list as an argv element instead of interpolating it into a shell
    string.

    Reachability — this only executes on the launcher='slurm' path
    (init_dist('slurm', ...)). Code that merely imports from BasicSR, e.g.
    from basicsr.archs.rrdbnet_arch import RRDBNet, never reaches it, and an
    attacker additionally needs control of the process environment. So for the many
    downstream users who depend on BasicSR only for its archs (Real-ESRGAN, GFPGAN
    and similar), the practical exposure looks like nil — worth knowing, since
    basicsr <= 1.4.2 matches every published release and so flags in dependency
    scanners with no version to upgrade to.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions