cbcvebase.
CVE-2021-41215
published 2021-11-05

CVE-2021-41215: TensorFlow is an open source platform for machine learning. In affected versions the shape inference code for `DeserializeSparse` can trigger a null pointer…

medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
TensorFlow is an open source platform for machine learning. In affected versions the shape inference code for `DeserializeSparse` can trigger a null pointer dereference. This is because the shape inference function assumes that the `serialize_sparse` tensor is a tensor with positive rank (and having `3` as the last dimension). The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, TensorFlow 2.5.2, and TensorFlow 2.4.4, as these are also affected and still in supported range.

Affected

12 ranges
VendorProductVersion rangeFixed in
debiantensorflow
googletensorflow< 2.4.42.4.4
googletensorflow
googletensorflow>= 2.5.0 < 2.5.22.5.2
inteloptimization_for_tensorflow>= 0 < 2.4.42.4.4
inteloptimization_for_tensorflow>= 0 < d3738dd70f1c9ceb547258cbb82d853da8771850d3738dd70f1c9ceb547258cbb82d853da8771850
inteloptimization_for_tensorflow>= 2.5.0 < 2.5.22.5.2
inteloptimization_for_tensorflow>= 2.6.0 < 2.6.12.6.1
inteloptimization_for_tensorflow>= 2.7.0rc0 < 2.7.02.7.0
tensorflowtensorflow< 2.4.42.4.4
tensorflowtensorflow
tensorflowtensorflow