{"api_version":"1","generated_at":"2026-07-23T15:32:55+00:00","cve":"CVE-2021-41209","urls":{"html":"https://cve.report/CVE-2021-41209","api":"https://cve.report/api/cve/CVE-2021-41209.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-41209","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-41209"},"summary":{"title":"CVE-2021-41209","description":"TensorFlow is an open source platform for machine learning. In affected versions the implementations for convolution operators trigger a division by 0 if passed empty filter tensor arguments. The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, TensorFlow 2.5.2, and TensorFlow 2.4.4, as these are also affected and still in supported range.","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2021-11-05 22:15:00","updated_at":"2021-11-09 18:40:00"},"problem_types":["CWE-369"],"metrics":[],"references":[{"url":"https://github.com/tensorflow/tensorflow/security/advisories/GHSA-6hpv-v2rx-c5g6","name":"https://github.com/tensorflow/tensorflow/security/advisories/GHSA-6hpv-v2rx-c5g6","refsource":"CONFIRM","tags":[],"title":"FPE in convolutions with zero size filters · Advisory · tensorflow/tensorflow · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/tensorflow/tensorflow/commit/f2c3931113eaafe9ef558faaddd48e00a6606235","name":"https://github.com/tensorflow/tensorflow/commit/f2c3931113eaafe9ef558faaddd48e00a6606235","refsource":"MISC","tags":[],"title":"Adding more validation checks to _ParallelConcatUpdate to avoid NPE. · tensorflow/tensorflow@f2c3931 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-41209","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-41209","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"41209","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"google","cpe5":"tensorflow","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"41209","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"google","cpe5":"tensorflow","cpe6":"2.7.0","cpe7":"rc0","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"41209","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"google","cpe5":"tensorflow","cpe6":"2.7.0","cpe7":"rc1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-41209","qid":"980174","title":"Python (pip) Security Update for tensorflow-gpu (GHSA-6hpv-v2rx-c5g6)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security-advisories@github.com","ID":"CVE-2021-41209","STATE":"PUBLIC","TITLE":"FPE in convolutions with zero size filters"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"tensorflow","version":{"version_data":[{"version_value":">= 2.6.0, < 2.6.1"},{"version_value":">= 2.5.0, < 2.5.2"},{"version_value":"< 2.4.4"}]}}]},"vendor_name":"tensorflow"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"TensorFlow is an open source platform for machine learning. In affected versions the implementations for convolution operators trigger a division by 0 if passed empty filter tensor arguments. The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, TensorFlow 2.5.2, and TensorFlow 2.4.4, as these are also affected and still in supported range."}]},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-369: Divide By Zero"}]}]},"references":{"reference_data":[{"name":"https://github.com/tensorflow/tensorflow/security/advisories/GHSA-6hpv-v2rx-c5g6","refsource":"CONFIRM","url":"https://github.com/tensorflow/tensorflow/security/advisories/GHSA-6hpv-v2rx-c5g6"},{"name":"https://github.com/tensorflow/tensorflow/commit/f2c3931113eaafe9ef558faaddd48e00a6606235","refsource":"MISC","url":"https://github.com/tensorflow/tensorflow/commit/f2c3931113eaafe9ef558faaddd48e00a6606235"}]},"source":{"advisory":"GHSA-6hpv-v2rx-c5g6","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2021-11-05 22:15:00","lastModifiedDate":"2021-11-09 18:40:00","problem_types":["CWE-369"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:N/A:P","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL","baseScore":2.1},"severity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.0","versionEndExcluding":"2.6.1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:*","versionStartIncluding":"2.5.0","versionEndExcluding":"2.5.2","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:google:tensorflow:2.7.0:rc1:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:google:tensorflow:2.7.0:rc0:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:*","versionStartIncluding":"2.4.0","versionEndExcluding":"2.4.4","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"41209","Ordinal":"216945","Title":"CVE-2021-41209","CVE":"CVE-2021-41209","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"41209","Ordinal":"1","NoteData":"TensorFlow is an open source platform for machine learning. In affected versions the implementations for convolution operators trigger a division by 0 if passed empty filter tensor arguments. The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, TensorFlow 2.5.2, and TensorFlow 2.4.4, as these are also affected and still in supported range.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"41209","Ordinal":"2","NoteData":"2021-11-05","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"41209","Ordinal":"3","NoteData":"2021-11-05","Type":"Other","Title":"Modified"}]}}}