PT-2021-18362 · Google · Tensorflow

·

CVE-2021-29611

·

Published

2021-05-14

·

Updated

2024-03-06

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions TensorFlow versions 2.3.3 through 2.4.2
Description Incomplete validation in SparseReshape results in a denial of service based on a CHECK-failure. The implementation has no validation that the input arguments specify a valid sparse tensor.
Recommendations For versions 2.3.3 and 2.4.2, update to version 2.5.0 or later to resolve the issue. For version 2.3.3, consider applying the patch from GitHub commit 1d04d7d93f4ed3854abf75d6b712d72c3f70d6b6 as a temporary workaround until the official update is available. For version 2.4.2, consider applying the patch from GitHub commit 1d04d7d93f4ed3854abf75d6b712d72c3f70d6b6 as a temporary workaround until the official update is available.

Exploit

Fix

RCE

Improper Initialization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-TENSORFLOW-2021-29611
CVE-2021-29611
GHSA-9RPC-5V9Q-5R7F
PYSEC-2021-248
PYSEC-2021-539
PYSEC-2021-737

Affected Products

Tensorflow