VDB

CVE-2021-29544

CVE-2021-29544 PUBLISHED CVSS 5.5 MEDIUM

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a `CHECK`-fail in `tf.raw_ops.QuantizeAndDequantizeV4Grad`. This is because the implementation does not validate the rank of the `input_*` tensors. In turn, this results in the tensors being passes as they are to `QuantizeAndDequantizePerChannelGradientImpl`. However, the `vec<T>` method, requires the rank to 1 and triggers a `CHECK` failure otherwise. The fix will be included in TensorFlow 2.5.0. We will also cherrypick this commit on TensorFlow 2.4.2 as this is the only other affected version.

EPSS 0.31% · 24.0th percentile

Risk Scores

CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.31%
24.0th percentile

Affected Products

VendorProductVersions
Bitnamitensorflow2.4.0
Bitnamitensorflow2.4.0

Timeline

  • May 14, 2021 CVE Published
  • May 15, 2021 EPSS Score
  • Jul 18, 2021 EPSS Score
  • Sep 18, 2021 EPSS Score
  • Nov 19, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Mar 23, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 24, 2022 EPSS Score
  • Jul 26, 2022 EPSS Score
  • Sep 26, 2022 EPSS Score
  • Nov 27, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›