id: PYSEC-2021-630 details: TensorFlow is an open source platform for machine learning. In affected versions the shape inference code for the `Cudnn*` operations in TensorFlow can be tricked into accessing invalid memory, via a heap buffer overflow. This occurs because the ranks of the `input`, `input_h` and `input_c` parameters are not validated, but code assumes they have certain values. The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, TensorFlow 2.5.2, and TensorFlow 2.4.4, as these are also affected and still in supported range. affected: - package: name: tensorflow-cpu ecosystem: PyPI purl: pkg:pypi/tensorflow-cpu ranges: - type: GIT repo: https://github.com/tensorflow/tensorflow events: - introduced: "0" - fixed: af5fcebb37c8b5d71c237f4e59c6477015c78ce6 - type: ECOSYSTEM events: - introduced: "0" - fixed: 2.4.4 - introduced: 2.5.0 - fixed: 2.5.2 - introduced: 2.6.0 - fixed: 2.6.1 - introduced: 2.7.0rc0 - fixed: 2.7.0 versions: - 1.15.0 - 2.1.0 - 2.1.1 - 2.1.2 - 2.1.3 - 2.1.4 - 2.2.0 - 2.2.1 - 2.2.2 - 2.2.3 - 2.3.0 - 2.3.1 - 2.3.2 - 2.3.3 - 2.3.4 - 2.4.0 - 2.4.1 - 2.4.2 - 2.4.3 - 2.5.0 - 2.5.1 - 2.6.0 - 2.7.0rc0 - 2.7.0rc1 references: - type: ADVISORY url: https://github.com/tensorflow/tensorflow/security/advisories/GHSA-cqv6-3phm-hcwx - type: FIX url: https://github.com/tensorflow/tensorflow/commit/af5fcebb37c8b5d71c237f4e59c6477015c78ce6 aliases: - CVE-2021-41221 - GHSA-cqv6-3phm-hcwx modified: "2021-12-09T06:35:10.512289Z" published: "2021-11-05T23:15:00Z"