TensorFlow is an open source platform for machine learning. In affected versions the implementation of `ParallelConcat` misses some input validation and can produce a division by 0. The fix will be...
Full analysis pending. Showing NVD description excerpt.
Affected Systems
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| tensorflow | pip | — | No patch |
| tensorflow | pip | — | No patch |
| tensorflow | pip | — | No patch |
| tensorflow | pip | — | No patch |
| tensorflow | pip | — | No patch |
| tensorflow | pip | >= 2.6.0, < 2.6.1 | 2.6.1 |
| tensorflow-cpu | pip | >= 0, < 2.4.4 | 2.4.4 |
| tensorflow-gpu | pip | >= 0, < 2.4.4 | 2.4.4 |
Severity & Risk
Recommended Action
Patch available
Update tensorflow to version 2.6.1
Update tensorflow-cpu to version 2.4.4
Update tensorflow-gpu to version 2.4.4
Compliance Impact
Compliance analysis pending. Sign in for full compliance mapping when available.
Technical Details
NVD Description
TensorFlow is an open source platform for machine learning. In affected versions the implementation of `ParallelConcat` misses some input validation and can produce a division by 0. The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, TensorFlow 2.5.2, and TensorFlow 2.4.4, as these are also affected and still in supported range.
Weaknesses (CWE)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H References
- github.com/tensorflow/tensorflow/commit/f2c3931113eaafe9ef558faaddd48e00a6606235 Patch 3rd Party
- github.com/tensorflow/tensorflow/security/advisories/GHSA-7v94-64hj-m82h 3rd Party
- github.com/advisories/GHSA-7v94-64hj-m82h
- github.com/pypa/advisory-database/tree/main/vulns/tensorflow-cpu/PYSEC-2021-616.yaml
- github.com/pypa/advisory-database/tree/main/vulns/tensorflow-gpu/PYSEC-2021-814.yaml
- github.com/pypa/advisory-database/tree/main/vulns/tensorflow/PYSEC-2021-399.yaml
- github.com/tensorflow/tensorflow/blob/8d72537c6abf5a44103b57b9c2e22c14f5f49698/tensorflow/core/kernels/inplace_ops.cc
- github.com/tensorflow/tensorflow/commit/9de11bdc2cf1284b2f635419bd3e6bbc7643eb2c
- github.com/tensorflow/tensorflow/commit/d11f21bbdfa54f3576ae860fc927bf23c675ebc0
- github.com/tensorflow/tensorflow/commit/e67caccea81167402c62977b5c521f2a8b261d6a
- github.com/tensorflow/tensorflow/commit/f2c3931113eaafe9ef558faaddd48e00a6606235
- github.com/tensorflow/tensorflow/security/advisories/GHSA-7v94-64hj-m82h
- nvd.nist.gov/vuln/detail/CVE-2021-41207
- github.com/tensorflow/tensorflow/commit/f2c3931113eaafe9ef558faaddd48e00a6606235 Patch 3rd Party
- github.com/tensorflow/tensorflow/security/advisories/GHSA-7v94-64hj-m82h 3rd Party