You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
For anyone landing here from the advisory, the concrete details:
The single sink is basicsr/utils/dist_util.py, in _init_dist_slurm:
addr=subprocess.getoutput(f'scontrol show hostname {node_list} | head -n1')
node_list is os.environ['SLURM_NODELIST'], and subprocess.getoutput runs
its argument through /bin/sh -c, so shell metacharacters in that variable are
interpreted. This is the only getoutput call in the codebase, and the fix is to
pass the node list as an argv element instead of interpolating it into a shell
string.
Reachability — this only executes on the launcher='slurm' path
(init_dist('slurm', ...)). Code that merely imports from BasicSR, e.g. from basicsr.archs.rrdbnet_arch import RRDBNet, never reaches it, and an
attacker additionally needs control of the process environment. So for the many
downstream users who depend on BasicSR only for its archs (Real-ESRGAN, GFPGAN
and similar), the practical exposure looks like nil — worth knowing, since basicsr <= 1.4.2 matches every published release and so flags in dependency
scanners with no version to upgrade to.
Is there any plan to fix this vulnerability? Will this be fix soon?