PT-2021-23181 · Google · Tensorflow

Mihaimaruseac

·

Published

2021-11-05

·

Updated

2024-03-06

·

CVE-2021-41209

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions TensorFlow versions prior to 2.7.0 TensorFlow version 2.6.1 TensorFlow version 2.5.2 TensorFlow version 2.4.4
Description The implementations for convolution operators in TensorFlow trigger a division by 0 if passed empty filter tensor arguments. This issue affects TensorFlow, an open source platform for machine learning.
Recommendations For versions prior to 2.7.0, update to TensorFlow 2.7.0 or later. For version 2.6.1, apply the cherrypicked commit to resolve the issue. For version 2.5.2, apply the cherrypicked commit to resolve the issue. For version 2.4.4, apply the cherrypicked commit to resolve the issue.

Fix

Divide By Zero

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-TENSORFLOW-2021-41209
CVE-2021-41209
GHSA-6HPV-V2RX-C5G6
OPENSUSE-SU-2024:12116-1
PYSEC-2021-401
PYSEC-2021-618
PYSEC-2021-816

Affected Products

Tensorflow