Safety vulnerability ID: 58486
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Tensorflow-macos versions 2.3.4, 2.4.3, 2.5.1 and 2.6.0 include a fix for CVE-2021-37674: In affected versions, an attacker can trigger a denial of service via a segmentation fault in "tf.raw_ops.MaxPoolGrad" caused by missing validation. The implementation (https://github.com/tensorflow/tensorflow/blob/460e000de3a83278fb00b61a16d161b1964f15f4/tensorflow/core/kernels/maxpooling_op.cc) misses some validation for the "orig_input" and "orig_output" tensors. The fixes for CVE-2021-29579 were incomplete. The Tensorflow team has patched the issue in GitHub commit 136b51f10903e044308cf77117c0ed9871350475.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-7ghq-fvr3-pj2x
https://github.com/tensorflow/tensorflow/blob/master/tensorflow/security/advisory/tfsa-2021-068.md
https://github.com/tensorflow/tensorflow/commit/136b51f10903e044308cf77117c0ed9871350475
Latest version: 2.16.2
TensorFlow is an open source machine learning framework for everyone.
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application