QID 982465
QID 982465: Python (pip) Security Update for tensorflow (GHSA-vfr4-x8j2-3rf9)
Security update has been released for tensorflow to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
The optimized implementation of the `TransposeConv` TFLite operator is [vulnerable to a division by zero error](https://github.com/tensorflow/tensorflow/blob/0d45ea1ca641b21b73bcf9c00e0179cda284e7e7/tensorflow/lite/kernels/internal/optimized/optimized_ops.h#L5221-L5222):
```cc
int height_col = (height + pad_t + pad_b - filter_h) / stride_h + 1;
int width_col = (width + pad_l + pad_r - filter_w) / stride_w + 1;
```
An attacker can craft a model such that `stride_{h,w}` values are 0. Code calling this function must validate these arguments.
The fix will be included in TensorFlow 2.5.0. We will also cherrypick this commit on TensorFlow 2.4.2, TensorFlow 2.3.3, TensorFlow 2.2.3 and TensorFlow 2.1.4, as these are also affected and still in supported range.
- GHSA-vfr4-x8j2-3rf9 -
github.com/advisories/GHSA-vfr4-x8j2-3rf9
CVEs related to QID 982465
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vfr4-x8j2-3rf9 | tensorflow |
|