Safety vulnerability ID: 57780
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Tensorflow-rocm version 2.3.4, 2.4.3, 2.5.1 and 2.6.0 include a fix for CVE-2021-37672:
In affected versions, an attacker can read from outside of bounds of heap allocated data by sending specially crafted illegal arguments to "tf.raw_ops.SdcaOptimizerV2". The implementation (https://github.com/tensorflow/tensorflow/blob/460e000de3a83278fb00b61a16d161b1964f15f4/tensorflow/core/kernels/sdca_internal.cc#L320-L353) does not check that the length of "example_labels" is the same as the number of examples. The Tensorflow team has patched the issue in GitHub commit a4e138660270e7599793fa438cd7b2fc2ce215a6.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-5hj3-vjjf-f5m7
https://github.com/tensorflow/tensorflow/commit/a4e138660270e7599793fa438cd7b2fc2ce215a6
Latest version: 2.14.0.600
TensorFlow is an open source machine learning framework for everyone.
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application