CVE-2021-41195: Integer Overflow or Wraparound
TensorFlow is an open source platform for machine learning. In affected versions the implementation of tf.math.segment_*
operations results in a CHECK
-fail related abort if a segment id in segment_ids
is large. This is similar to CVE-2021-29584 (and similar other reported vulnerabilities in TensorFlow, localized to specific APIs): the implementation computes the output shape using AddDim
. However, if the number of elements in the tensor overflows an int64_t
value, AddDim
results in a CHECK
failure which provokes a std::abort
. Instead, code should use AddDimWithStatus
. The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, TensorFlow 2.5.2, and TensorFlow 2.4.4, as these are also affected and still in supported range.
References
- github.com/advisories/GHSA-cq76-mxrc-vchh
- github.com/tensorflow/tensorflow/commit/e9c81c1e1a9cd8dd31f4e83676cab61b60658429
- github.com/tensorflow/tensorflow/issues/46888
- github.com/tensorflow/tensorflow/pull/51733
- github.com/tensorflow/tensorflow/security/advisories/GHSA-cq76-mxrc-vchh
- nvd.nist.gov/vuln/detail/CVE-2021-41195
Detect and mitigate CVE-2021-41195 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →