CVE-2018-7577: Google Snappy

High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Memcpy parameter overlap in Google Snappy library 1.1.4, as used in Google TensorFlow before 1.7.1, could result in a crash or read from other parts of process memory.

Affected products

  • Google Snappy: version 1.1.4 only
  • Google Tensorflow: before 1.7.1 (fixed in 1.7.1)

Published 2019-04-24. Last modified 2026-06-17.