icon

We found results for “

CVE-2021-29544

Good to know:

icon

Date: May 14, 2021

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a "CHECK"-fail in "tf.raw_ops.QuantizeAndDequantizeV4Grad". This is because the implementation does not validate the rank of the "input_*" tensors. In turn, this results in the tensors being passes as they are to "QuantizeAndDequantizePerChannelGradientImpl". However, the "vec<T>" method, requires the rank to 1 and triggers a "CHECK" failure otherwise. The fix will be included in TensorFlow 2.5.0. We will also cherrypick this commit on TensorFlow 2.4.2 as this is the only other affected version.

Language: C++

Severity Score

Severity Score

Weakness Type (CWE)

Improper Check for Unusual or Exceptional Conditions

CWE-754

Top Fix

icon

Upgrade Version

Upgrade to version tensorflow-cpu - 2.4.2;tensorflow - 2.4.2;tensorflow-gpu - 2.4.2;tensorflow-gpu - 2.2.0rc0

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): LOCAL
Attack Complexity (AC): HIGH
Privileges Required (PR): LOW
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): LOW

CVSS v2

Base Score:
Access Vector (AV): LOCAL
Access Complexity (AC): LOW
Authentication (AU): NONE
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): PARTIAL
Additional information:

Do you need more information?

Contact Us