CVE-2021-41227
Summary
| CVE | CVE-2021-41227 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-11-05 23:15:00 UTC |
| Updated | 2021-11-10 13:18:00 UTC |
| Description | TensorFlow is an open source platform for machine learning. In affected versions the `ImmutableConst` operation in TensorFlow can be tricked into reading arbitrary memory contents. This is because the `tstring` TensorFlow string class has a special case for memory mapped strings but the operation itself does not offer any support for this datatype. The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, TensorFlow 2.5.2, and TensorFlow 2.4.4, as these are also affected and still in supported range. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Add error checking to ImmutableConst OP that strings are not yet supp… · tensorflow/tensorflow@1cb6bb6 · GitHub |
MISC |
github.com |
|
| Arbitrary memory read in `ImmutableConst` · Advisory · tensorflow/tensorflow · GitHub |
CONFIRM |
github.com |
|
| Fix macros for converting little endian to host for TF_TSRT_OFFSET Ge… · tensorflow/tensorflow@3712a2d · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 980192 Python (pip) Security Update for tensorflow-gpu (GHSA-j8c8-67vp-6mx7)