PT-2021-21802 · Google · Tensorflow

Published

2021-08-12

·

Updated

2024-03-06

·

CVE-2021-37683

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions TensorFlow versions prior to 2.6.0 TensorFlow version 2.5.1 TensorFlow version 2.4.3 TensorFlow version 2.3.4
Description The implementation of division in TFLite is vulnerable to a division by 0 error. There is no check that the divisor tensor does not contain zero elements.
Recommendations For TensorFlow versions prior to 2.6.0, update to version 2.6.0 or later. For TensorFlow version 2.5.1, apply the patch from GitHub commit 1e206baedf8bef0334cca3eb92bab134ef525a28. For TensorFlow version 2.4.3, apply the patch from GitHub commit 1e206baedf8bef0334cca3eb92bab134ef525a28. For TensorFlow version 2.3.4, apply the patch from GitHub commit 1e206baedf8bef0334cca3eb92bab134ef525a28.

Fix

Divide By Zero

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-TENSORFLOW-2021-37683
CVE-2021-37683
GHSA-RHRQ-64MQ-HF9H
OPENSUSE-SU-2022:10014-1
OPENSUSE-SU-2024:12116-1
PYSEC-2021-305
PYSEC-2021-596
PYSEC-2021-794

Affected Products

Tensorflow