PT-2021-18347 · Google · Tensorflow

CVE-2021-29596

·

Published

2021-05-14

·

Updated

2024-03-06

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TensorFlow versions prior to 2.5.0 TensorFlow versions 2.4.2 and earlier TensorFlow versions 2.3.3 and earlier TensorFlow versions 2.2.3 and earlier TensorFlow versions 2.1.4 and earlier
Description The implementation of the EmbeddingLookup TFLite operator in TensorFlow is vulnerable to a division by zero error. An attacker can craft a model such that the first dimension of the value input is 0, causing the error.
Recommendations For versions prior to 2.5.0, update to TensorFlow 2.5.0 or later. For versions 2.4.2 and earlier, update to TensorFlow 2.4.2 or later. For versions 2.3.3 and earlier, update to TensorFlow 2.3.3 or later. For versions 2.2.3 and earlier, update to TensorFlow 2.2.3 or later. For versions 2.1.4 and earlier, update to TensorFlow 2.1.4 or later.

Exploit

Fix

Divide By Zero

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-TENSORFLOW-2021-29596
CVE-2021-29596
GHSA-4VRF-FF7V-HPGR
PYSEC-2021-233
PYSEC-2021-524
PYSEC-2021-722

Affected Products

Tensorflow