TensorFlow before 1.7.0 has an integer overflow that causes an out-of-bounds read, possibly causing disclosure of the contents of process memory. This occurs in the DecodeBmp feature of the BMP decoder in core/kernels/decodebmpop.cc.
"https://github.com/pypa/advisory-database/blob/main/vulns/tensorflow-gpu/PYSEC-2020-304.yaml"