CVE-2021-29559: Out-of-bounds Read
(updated )
TensorFlow is an end-to-end open source platform for machine learning. An attacker can access data outside of bounds of heap allocated array in tf.raw_ops.UnicodeEncode
. This is because the implementation assumes that the input_value
/input_splits
pair specify a valid sparse tensor.
References
Detect and mitigate CVE-2021-29559 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →