PT-2021-23191 · Google · Tensorflow

Published

2021-11-05

·

Updated

2024-03-06

·

CVE-2021-41218

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions TensorFlow versions prior to 2.7.0 TensorFlow versions 2.6.1 and earlier TensorFlow versions 2.5.2 and earlier TensorFlow versions 2.4.4 and earlier
Description TensorFlow is an open source platform for machine learning. In affected versions, the shape inference code for AllToAll can be made to execute a division by 0. This occurs whenever the split count argument is 0.
Recommendations For versions prior to 2.7.0, update to TensorFlow 2.7.0 or later. For versions 2.6.1 and earlier, update to TensorFlow 2.6.1 or later. For versions 2.5.2 and earlier, update to TensorFlow 2.5.2 or later. For versions 2.4.4 and earlier, update to TensorFlow 2.4.4 or later. As a temporary workaround, consider avoiding the use of the split count argument with a value of 0 in the AllToAll function until a patch is available.

Fix

Divide By Zero

Weakness Enumeration

Related Identifiers

BIT-TENSORFLOW-2021-41218
CVE-2021-41218
GHSA-9CRF-C6QR-R273
OPENSUSE-SU-2024:12116-1
PYSEC-2021-410
PYSEC-2021-627
PYSEC-2021-825

Affected Products

Tensorflow