id: PYSEC-2021-472 details: TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a `CHECK`-fail in `tf.raw_ops.QuantizeAndDequantizeV4Grad`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/95078c145b5a7a43ee046144005f733092756ab5/tensorflow/core/kernels/quantize_and_dequantize_op.cc#L162-L163) does not validate the rank of the `input_*` tensors. In turn, this results in the tensors being passes as they are to `QuantizeAndDequantizePerChannelGradientImpl`(https://github.com/tensorflow/tensorflow/blob/95078c145b5a7a43ee046144005f733092756ab5/tensorflow/core/kernels/quantize_and_dequantize_op.h#L295-L306). However, the `vec` method, requires the rank to 1 and triggers a `CHECK` failure otherwise. The fix will be included in TensorFlow 2.5.0. We will also cherrypick this commit on TensorFlow 2.4.2 as this is the only other affected version. affected: - package: name: tensorflow-cpu ecosystem: PyPI purl: pkg:pypi/tensorflow-cpu ranges: - type: GIT repo: https://github.com/tensorflow/tensorflow events: - introduced: "0" - fixed: 20431e9044cf2ad3c0323c34888b192f3289af6b - type: ECOSYSTEM events: - introduced: "0" - fixed: 2.2.0rc0 - introduced: 2.2.0 - fixed: 2.3.0rc0 - introduced: 2.3.0 - fixed: 2.3.4 - introduced: 2.4.0 - fixed: 2.4.3 versions: - 1.15.0 - 2.1.0 - 2.1.1 - 2.1.2 - 2.1.3 - 2.1.4 - 2.2.0 - 2.2.1 - 2.2.2 - 2.2.3 - 2.3.0 - 2.3.1 - 2.3.2 - 2.3.3 - 2.4.0 - 2.4.1 - 2.4.2 references: - type: FIX url: https://github.com/tensorflow/tensorflow/commit/20431e9044cf2ad3c0323c34888b192f3289af6b - type: ADVISORY url: https://github.com/tensorflow/tensorflow/security/advisories/GHSA-6g85-3hm8-83f9 aliases: - CVE-2021-29544 - GHSA-6g85-3hm8-83f9 modified: "2021-12-09T06:34:50.195889Z" published: "2021-05-14T20:15:00Z"