CVE-2021-41218
Summary
| CVE | CVE-2021-41218 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-11-05 22:15:00 UTC |
| Updated | 2021-11-09 18:43:00 UTC |
| Description | TensorFlow is an open source platform for machine learning. In affected versions the shape inference code for `AllToAll` can be made to execute a division by 0. This occurs whenever the `split_count` argument is 0. The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, TensorFlow 2.5.2, and TensorFlow 2.4.4, as these are also affected and still in supported range. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Update TPU AllToAll op to avoid divide by 0. · tensorflow/tensorflow@a8ad3e5 · GitHub |
MISC |
github.com |
|
| Integer division by 0 in `tf.raw_ops.AllToAll` · Advisory · tensorflow/tensorflow · GitHub |
CONFIRM |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 980183 Python (pip) Security Update for tensorflow-gpu (GHSA-9crf-c6qr-r273)