CVE-2021-29584: Integer Overflow or Wraparound
(updated )
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a CHECK
-fail in caused by an integer overflow in constructing a new tensor shape. This is because the implementation builds a dense shape without checking that the dimensions would not result in overflow. The TensorShape
constructor uses a CHECK
operation which triggers when InitDims
returns a non-OK status. This is a legacy implementation of the constructor and operations should use BuildTensorShapeBase
or AddDimWithStatus
to prevent CHECK
-failures in the presence of overflows.
References
Detect and mitigate CVE-2021-29584 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →