 
                        We found results for “”
CVE-2021-41195
Good to know:
 
                                    Date: November 5, 2021
TensorFlow is an open source platform for machine learning. In affected versions the implementation of "tf.math.segment_*" operations results in a "CHECK"-fail related abort (and denial of service) if a segment id in "segment_ids" is large. This is similar to CVE-2021-29584 (and similar other reported vulnerabilities in TensorFlow, localized to specific APIs): the implementation (both on CPU and GPU) computes the output shape using "AddDim". However, if the number of elements in the tensor overflows an "int64_t" value, "AddDim" results in a "CHECK" failure which provokes a "std::abort". Instead, code should use "AddDimWithStatus". The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, TensorFlow 2.5.2, and TensorFlow 2.4.4, as these are also affected and still in supported range.
Language: Python
Severity Score
Related Resources (10)
Severity Score
Weakness Type (CWE)
Integer Overflow or Wraparound
CWE-190Top Fix
 
                                    Upgrade Version
Upgrade to version tensorflow - 2.6.1;tensorflow - 2.5.2;tensorflow - 2.4.4;tensorflow-cpu - 2.5.2;tensorflow-cpu - 2.6.1;tensorflow-cpu - 2.4.4;tensorflow-gpu - 2.6.1;tensorflow-gpu - 2.5.2;tensorflow-gpu - 2.4.4
CVSS v3.1
| Base Score: |  | 
|---|---|
| Attack Vector (AV): | LOCAL | 
| Attack Complexity (AC): | LOW | 
| Privileges Required (PR): | LOW | 
| User Interaction (UI): | NONE | 
| Scope (S): | UNCHANGED | 
| Confidentiality (C): | NONE | 
| Integrity (I): | NONE | 
| Availability (A): | HIGH | 
CVSS v2
| Base Score: |  | 
|---|---|
| Access Vector (AV): | LOCAL | 
| Access Complexity (AC): | LOW | 
| Authentication (AU): | NONE | 
| Confidentiality (C): | NONE | 
| Integrity (I): | NONE | 
| Availability (A): | PARTIAL | 
| Additional information: | 
 Vulnerabilities
                        Vulnerabilities
                 Projects
                        Projects
                 Vulnerability Disclosure
                        Vulnerability Disclosure
                 About Us
                    About Us
                 Contact Us
                    Contact Us
                

