CVE-2021-29523: Integer Overflow or Wraparound
(updated )
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a CHECK
-fail in tf.raw_ops.AddManySparseToTensorsMap
. This is because the implementation takes the values specified in sparse_shape
as dimensions for the output shape. The TensorShape
constructor uses a CHECK
operation which triggers when InitDims
returns a non-OK status. This is a legacy implementation of the constructor and operations should use BuildTensorShapeBase
or AddDimWithStatus
to prevent CHECK
-failures in the presence of overflows.
References
Detect and mitigate CVE-2021-29523 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →