cbcvebase.
CVE-2021-41205
published 2021-11-05

CVE-2021-41205: TensorFlow is an open source platform for machine learning. In affected versions the shape inference functions for the `QuantizeAndDequantizeV*` operations can…

PriorityP428high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.15%
4.5th percentile
TensorFlow is an open source platform for machine learning. In affected versions the shape inference functions for the `QuantizeAndDequantizeV*` operations can trigger a read outside of bounds of heap allocated array. The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, TensorFlow 2.5.2, and TensorFlow 2.4.4, as these are also affected and still in supported range.

Affected

12 ranges
VendorProductVersion rangeFixed in
debiantensorflow
googletensorflow< 2.4.42.4.4
googletensorflow>= 2.5.0 < 2.5.22.5.2
googletensorflow>= 2.6.0 < 2.6.12.6.1
inteloptimization_for_tensorflow>= 0 < 2.4.42.4.4
inteloptimization_for_tensorflow>= 0 < 7cf73a2274732c9d82af51c2bc2cf90d13cd7e6d7cf73a2274732c9d82af51c2bc2cf90d13cd7e6d
inteloptimization_for_tensorflow>= 2.5.0 < 2.5.22.5.2
inteloptimization_for_tensorflow>= 2.6.0 < 2.6.12.6.1
inteloptimization_for_tensorflow>= 2.7.0rc0 < 2.7.02.7.0
tensorflowtensorflow< 2.4.42.4.4
tensorflowtensorflow
tensorflowtensorflow

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:N/A:P
vendor_debian7.1LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.