cbcvebase.
CVE-2021-41221
published 2021-11-05

CVE-2021-41221: TensorFlow is an open source platform for machine learning. In affected versions the shape inference code for the `Cudnn*` operations in TensorFlow can be…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.21%
11.9th percentile
TensorFlow is an open source platform for machine learning. In affected versions the shape inference code for the `Cudnn*` operations in TensorFlow can be tricked into accessing invalid memory, via a heap buffer overflow. This occurs because the ranks of the `input`, `input_h` and `input_c` parameters are not validated, but code assumes they have certain values. The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, TensorFlow 2.5.2, and TensorFlow 2.4.4, as these are also affected and still in supported range.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiantensorflow
googletensorflow
googletensorflow>= 2.4.0 < 2.4.42.4.4
googletensorflow>= 2.5.0 < 2.5.22.5.2
googletensorflow>= 2.6.0 < 2.6.12.6.1
inteloptimization_for_tensorflow>= 0 < af5fcebb37c8b5d71c237f4e59c6477015c78ce6af5fcebb37c8b5d71c237f4e59c6477015c78ce6
inteloptimization_for_tensorflow>= 0 < 2.4.42.4.4
inteloptimization_for_tensorflow>= 2.5.0 < 2.5.22.5.2
inteloptimization_for_tensorflow>= 2.6.0 < 2.6.12.6.1
inteloptimization_for_tensorflow>= 2.7.0rc0 < 2.7.02.7.0
tensorflowtensorflow< 2.4.42.4.4
tensorflowtensorflow
tensorflowtensorflow

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_debian7.8LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.