 
                        We found results for “”
CVE-2021-41213
Good to know:
 
                                    Date: November 5, 2021
TensorFlow is an open source platform for machine learning. In affected versions the code behind "tf.function" API can be made to deadlock when two "tf.function" decorated Python functions are mutually recursive. This occurs due to using a non-reentrant "Lock" Python object. Loading any model which contains mutually recursive functions is vulnerable. An attacker can cause denial of service by causing users to load such models and calling a recursive "tf.function", although this is not a frequent scenario. The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, TensorFlow 2.5.2, and TensorFlow 2.4.4, as these are also affected and still in supported range.
Language: Python
Severity Score
Related Resources (8)
Severity Score
Top Fix
 
                                    Upgrade Version
Upgrade to version tensorflow-cpu - 2.6.1;tensorflow-cpu - 2.5.2;tensorflow-cpu - 2.4.4;tensorflow-gpu - 2.6.1;tensorflow-gpu - 2.5.2;tensorflow-gpu - 2.4.4;tensorflow - 2.6.1;tensorflow - 2.5.2;tensorflow - 2.4.4
CVSS v3.1
| Base Score: |  | 
|---|---|
| Attack Vector (AV): | LOCAL | 
| Attack Complexity (AC): | LOW | 
| Privileges Required (PR): | LOW | 
| User Interaction (UI): | NONE | 
| Scope (S): | UNCHANGED | 
| Confidentiality (C): | NONE | 
| Integrity (I): | NONE | 
| Availability (A): | HIGH | 
CVSS v2
| Base Score: |  | 
|---|---|
| Access Vector (AV): | NETWORK | 
| Access Complexity (AC): | MEDIUM | 
| Authentication (AU): | NONE | 
| Confidentiality (C): | NONE | 
| Integrity (I): | NONE | 
| Availability (A): | PARTIAL | 
| Additional information: | 
 Vulnerabilities
                        Vulnerabilities
                 Projects
                        Projects
                 Vulnerability Disclosure
                        Vulnerability Disclosure
                 About Us
                    About Us
                 Contact Us
                    Contact Us
                

